Drupal Webform Module Cross Site Scripting Vulnerability
BID:65528
Info
Drupal Webform Module Cross Site Scripting Vulnerability
| Bugtraq ID: | 65528 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8318 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2014 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Maurits Lawende |
| Vulnerable: |
Drupal Webform 7.x-4.0 Drupal Webform 7.x-3.18 Drupal Webform 7.x-3.0 Drupal Webform 6.x-3.18 Drupal Webform 6.X-3.0 |
| Not Vulnerable: |
Drupal Webform 7.x-4.0-beta2 Drupal Webform 7.x-3.20 Drupal Webform 6.x-3.20 |
Exploit / POC
Drupal Webform Module Cross Site Scripting Vulnerability
Attackers can exploit this issue using browser. To exploit a cross-site scripting issue the attacker needs to entice a user into following a malicious URI.
Attackers can exploit this issue using browser. To exploit a cross-site scripting issue the attacker needs to entice a user into following a malicious URI.
Solution / Fix
Drupal Webform Module Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.