First published: Fri Sep 11 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zendesk Zendesk Feedback Tab | =7.x-1.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-6921 is categorized as moderate due to the possibility of remote script injection.
To fix CVE-2015-6921, you should update the Zendesk Feedback Tab module to version 7.x-1.1 or later.
CVE-2015-6921 affects Drupal users utilizing Zendesk Feedback Tab module version 7.x-1.x prior to 7.x-1.1.
CVE-2015-6921 is a cross-site scripting (XSS) vulnerability that allows script injection through the Zendesk Feedback Tab module.
Remote administrators with the "Configure Zendesk Feedback Tab" permission can exploit CVE-2015-6921 through unspecified vectors.