CVE-2014-4303

Touch theme 7.x-1.x - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter and (2) Facebook username settings.

Scores

EPSS 0.0037
EPSS Percentile 58.3%

Details

CWE
CWE-79
Status published
Products (10)
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
drupac/touch
n/a/n/a
Published Jun 18, 2014
Tracked Since Feb 18, 2026