CVE-2014-8319
17.10.2014, 14:55
Cross-site scripting (XSS) vulnerability in the easy_social_admin_summary function in the Easy Social module 7.x-2.x before 7.x-2.11 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a block title.
Vendor | Product | Version |
---|---|---|
easy_social_project | easy_social | 7.x-2.0:x |
easy_social_project | easy_social | 7.x-2.1:x |
easy_social_project | easy_social | 7.x-2.2:x |
easy_social_project | easy_social | 7.x-2.3:x |
easy_social_project | easy_social | 7.x-2.4:x |
easy_social_project | easy_social | 7.x-2.5:x |
easy_social_project | easy_social | 7.x-2.6:x |
easy_social_project | easy_social | 7.x-2.7:x |
easy_social_project | easy_social | 7.x-2.8:x |
easy_social_project | easy_social | 7.x-2.9:x |
easy_social_project | easy_social | 7.x-2.10:x |
𝑥
= Vulnerable software versions
References