Arbitrary Web Script Injection via Group Title in Organic Groups (OG) Module for Drupal
CVE-2012-3800 · LOW Severity
AV:N/AC:H/AU:S/C:N/I:P/A:N
Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.
Learn more about our Web App Pen Testing.