Vulnerability Bulletins

SA-CORE-2013-001 - Drupal core - Multiple vulnerabilities

   
Affected software Drupal
 
Advisory ID: DRUPAL-SA-CORE-2013-001Project: Drupal coreVersion: 6.x, 7.xDate: 2013-January-16Security risk: Highly criticalExploitable from: RemoteVulnerability: Cross Site Scripting, Access bypassDescriptionMultiple vulnerabilities were fixed in the supported Drupal core versions 6 and 7.Cross-site scripting (Various core and contributed modules - Drupal 6 and 7)A reflected cross-site scripting vulnerability (XSS) was identified in certain Drupal JavaScript functions that pass unexpected user

More info:

https://www.drupal.org/SA-CORE-2013-001