Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web script or HTML via vectors related to deleting a Path-based Metatag.
References
Link | Resource |
---|---|
https://www.drupal.org/node/2295975 | Patch Vendor Advisory |
https://www.drupal.org/node/2296511 | Vendor Advisory |
https://www.drupal.org/node/2295975 | Patch Vendor Advisory |
https://www.drupal.org/node/2296511 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.drupal.org/node/2295975 - Patch, Vendor Advisory | |
References | () https://www.drupal.org/node/2296511 - Vendor Advisory |
Information
Published : 2014-12-10 20:59
Updated : 2025-04-12 10:46
NVD link : CVE-2014-9362
Mitre link : CVE-2014-9362
CVE.ORG link : CVE-2014-9362
JSON object : View
Products Affected
meta_tags_quick_project
- meta_tags_quick
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')