CVE-2014-7869 Information

Description

Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the \administer contexts\ permission to inject arbitrary web script or HTML via unspecified vectors.

Reference

http://secunia.com/advisories/58307 http://www.securityfocus.com/bid/67173 https://www.drupal.org/node/2253103 https://www.drupal.org/node/2254853

Share on: