|
|
Log in / Subscribe / Register

drupal-cck: cross site scripting

Package(s):drupal-cck CVE #(s):
Created:November 7, 2008 Updated:November 24, 2008
Description: From the Drupal advisory: The Content Construction Kit (CCK) allows certain privileged users to add custom fields to content types using a web browser.

Some field labels and content-type names are displayed without appropriate filtering in the administrative interface. Malicious users with the "administer content" permission are able to exploit this issue and insert arbitrary HTML and script code into pages. Such a cross site scripting attack (XSS) may lead to the malicious user gaining full administrative access.

This is only an issue if you need any role separation between administrators and users with the "administer content" permission.

Alerts:
Fedora FEDORA-2008-10000 drupal-cck 2008-11-22
Fedora FEDORA-2008-9479 drupal-cck 2008-11-07

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds