Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Dismissed
updated 1 month ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @pyrox0 removed package smiley-sans
  • @pyrox0 accepted
  • @LeSuisse dismissed
Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions …

Cross-site scripting (XSS) vulnerability in the Smiley module 6.x-1.x versions prior to 6.x-1.1 and Smileys module 6.x-1.x versions prior to 6.x-1.1 for Drupal allows remote authenticated users with the "administer smiley" permission to inject arbitrary web script or HTML via a smiley acronym.

References

Affected products

Smiley
  • ==6.x-1.x versions prior to 6.x-1.1
Smileys
  • ==6.x-1.x versions prior to 6.x-1.1
Ignored packages (1)
Does not apply to the font.