mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
804 B
804 B
CVE-2012-3800
Description
Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.
POC
Reference
- http://drupalcode.org/project/og.git/commitdiff/d48fef5
- http://drupalcode.org/project/og.git/commitdiff/d48fef5
Github
No PoCs found on GitHub currently.