CVE-2016-3144: XSS
Published Apr 15, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.
Affected Software
3 affected components
Fourkitchens Block Class Drupal=7.x-2.0
Fourkitchens Block Class Drupal=7.x-2.1
Fedoraproject Fedora=24
Remediation
Patch Available
Patch Available
Event History
Apr 15, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3144?
CVE-2016-3144 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2016-3144?
To fix CVE-2016-3144, update the Block Class module to version 7.x-2.2 or later.
3
Who is affected by CVE-2016-3144?
CVE-2016-3144 affects remote authenticated users with the 'Administer block classes' permission in Drupal.
4
What can an attacker do with CVE-2016-3144?
An attacker can inject arbitrary web scripts or HTML via a class name, potentially compromising the application.
5
In which versions of the Block Class module is CVE-2016-3144 present?
CVE-2016-3144 is present in the Block Class module versions 7.x-2.0 and 7.x-2.1.