MEDIUM
The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site
Published Feb 4, 2011
6.8
MEDIUMCVSS 2.0
EPSS 2.06%
Description
Affected products
Remediation
Metrics
References (6)
Change history (0)
No recorded changes yet.