CVE-2014-4303
N/A
N/A
Summary
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter and (2) Facebook username settings.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/68045
- https://drupal.org/node/2284415
- http://secunia.com/advisories/58828
- https://drupal.org/node/2269483
References
- http://www.securityfocus.com/bid/68045
- https://drupal.org/node/2284415
- http://secunia.com/advisories/58828
- https://drupal.org/node/2269483
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.