Cross-Site Scripting Vulnerability in Facebook Album Fetcher for Drupal
CVE-2015-3390
Currently unrated
Key Information:
- Status
- Vendor
- CVE Published:
- 21 April 2015
What is CVE-2015-3390?
A Cross-Site Scripting (XSS) vulnerability exists in the Facebook Album Fetcher module for Drupal. This flaw allows remote authenticated users with the 'access administration pages' permission to insert arbitrary scripts or HTML code through unspecified vectors. The vulnerability poses risks for web application security by enabling attackers to manipulate user sessions and potentially compromise sensitive information. Proper handling and validation of user inputs are essential to mitigate this vulnerability and protect Drupal installations.