CVE-2015-5513
EUVD-2015-546818.08.2015, 18:00
Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML via unspecified vectors related to a login link.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| niif | shibboleth_authentication | 6.x-4.0:x |
| niif | shibboleth_authentication | 6.x-4.1:x |
| niif | shibboleth_authentication | 6.x-4.2rc1:x |
| niif | shibboleth_authentication | 7.x-4.0:x |
| niif | shibboleth_authentication | 7.x-4.1:x |
| niif | shibboleth_authentication | 7.x-4.2:x |
𝑥
= Vulnerable software versions
References