CVE-2015-5513
18.08.2015, 18:00
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML via unspecified vectors related to a login link.
Vendor | Product | Version |
---|---|---|
niif | shibboleth_authentication | 6.x-4.0:x |
niif | shibboleth_authentication | 6.x-4.1:x |
niif | shibboleth_authentication | 6.x-4.2rc1:x |
niif | shibboleth_authentication | 7.x-4.0:x |
niif | shibboleth_authentication | 7.x-4.1:x |
niif | shibboleth_authentication | 7.x-4.2:x |
𝑥
= Vulnerable software versions
References