CVE Database
/

CVE-2011-3373

Back to search

CVE-2011-3373

Published: Nov 25, 2019

Modified: Aug 6, 2024

PUBLISHED

Description

Drupal Views Builk Operations (VBO) module 6.x-1.0 through 6.x-1.10 does not properly escape the vocabulary help when the vocabulary has had user tagging enabled and the "Modify node taxonomy terms" action is used. A remote attacker could provide a specially-crafted URL that could lead to cross-site scripting (XSS) attack.

VendorProductVersions

drupal6-views_bulk_operations

drupal6-views_bulk_operations

affected
6.x-1.0 through 6.x-1.10

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2011-3373 - Security Vulnerability | QwikSec