Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.
2016-04-15T15:59:02.220
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | fourkitchens | block_class | 7.x-2.0 | Yes |
| Application | fourkitchens | block_class | 7.x-2.1 | Yes |
| Operating System | fedoraproject | fedora | 24 | Yes |