Liran Tal 10/28/2013

Advanced Poll 6.x versions – XSS Vulnerability

Read Original

The article reports a cross-site scripting (XSS) vulnerability discovered in the Advanced Poll module for Drupal (versions 6.x-3.x and earlier). It explains the security risk, affected versions, and that exploitation requires poll edit permissions. The author, Liran Tal, provided a patch which was submitted to the Drupal issue queue.

Advanced Poll 6.x versions – XSS Vulnerability

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week