LWN.net Logo

drupal7-theme-zen: cross-site scripting

Package(s):drupal7-theme-zen CVE #(s):CVE-2013-4275
Created:September 3, 2013 Updated:September 5, 2013
Description: From the drupal bug report:

Zen doesn't sufficiently escape the breadcrumb separator field, allowing a possible XSS exploit.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer themes".

Alerts:
Fedora FEDORA-2013-15142 2013-09-01
Fedora FEDORA-2013-15147 2013-09-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds