CVE-2013-4140
29.07.2013, 23:27
Cross-site scripting (XSS) vulnerability in the TinyBox (Simple Splash) module before 7.x-2.2 for Drupal allows remote authenticated users with the "administer tinybox" permission to inject arbitrary web script or HTML via unspecified vectors.
Vendor | Product | Version |
---|---|---|
drupalisme | tinybox | 𝑥 ≤ 7.x-2.1 |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.0:x |
drupalisme | tinybox | 7.x-1.1:x |
drupalisme | tinybox | 7.x-2.0:x |
𝑥
= Vulnerable software versions
References