Arbitrary Web Script Injection via Group Title in Organic Groups (OG) Module for Drupal

Arbitrary Web Script Injection via Group Title in Organic Groups (OG) Module for Drupal

CVE-2012-3800 · LOW Severity

AV:N/AC:H/AU:S/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.

Learn more about our Web App Pen Testing.