CVE-2014-7980
Zen theme for Drupal 7.x-3.x < 7.x-3.3 and 7.x-5.x < 7.x-5.5 - Authenticated Stored XSS via Theme Settings
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.
References (5)
Core 5
Core References
Patch x_refsource_confirm
https://www.drupal.org/node/2254837
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/67175
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/58318
Patch x_refsource_misc
http://drupal.org/node/2254925
Patch x_refsource_confirm
https://www.drupal.org/node/2254835
Scores
EPSS
0.0023
EPSS Percentile
45.9%
Details
CWE
CWE-79
Status
published
Products (8)
drupal/zen
7.x-3.0
drupal/zen
7.x-3.1
drupal/zen
7.x-3.2
drupal/zen
7.x-5.0
drupal/zen
7.x-5.1
drupal/zen
7.x-5.2
drupal/zen
7.x-5.3
drupal/zen
7.x-5.4
Published
Oct 08, 2014
Tracked Since
Feb 18, 2026