Drupal Orejime
- < 2.0.16
A cross-site scripting (XSS) vulnerability has been identified in the Drupal Orejime module, affecting versions prior to 2.0.16. The issue arises because the IframeConsent element does not properly escape HTML attribute values, allowing an attacker to inject arbitrary JavaScript if they can create an <iframe-consent> tag. Exploitation requires a text format that permits such tags with alt attributes, along with a role that allows content creation or modification in a compatible field.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Users of the 2.x branch of Orejime should upgrade to Orejime version 2.0.16.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.