|
|
| |
|
| |
drupal7-theme-zen: cross-site scripting
| Package(s): | drupal7-theme-zen |
CVE #(s): | CVE-2013-4275
|
| Created: | September 3, 2013 |
Updated: | September 5, 2013 |
| Description: |
From the drupal bug report:
Zen doesn't sufficiently escape the breadcrumb separator field, allowing a possible XSS exploit.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer themes". |
| Alerts: |
|
( Log in to post comments)
|
|
|