3.5
CVSSv2

CVE-2014-7980

Published: 08/10/2014 Updated: 09/10/2014
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x prior to 7.x-3.3 and 7.x-5.x prior to 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal zen 7.x-5.3

drupal zen 7.x-5.2

drupal zen 7.x-5.1

drupal zen 7.x-5.0

drupal zen 7.x-3.2

drupal zen 7.x-3.0

drupal zen 7.x-3.1

drupal zen 7.x-5.4