Project:
Date:
2018-July-11
Security risk:
Vulnerability:
Cross Site Scripting
Description:
This theme features 7 color styles, 12 collapsible regions, suckerfish menus, fluid or fixed widths, and lots more.
The theme doesn't sufficiently sanitize user input.
This vulnerability is mitigated by the fact that the theme is only exploitable with non-default settings and under certain site configurations.
Solution:
Install the latest version:
- If you use the NewsFlash theme for Drupal 7.x, upgrade to NewsFlash 7.x-2.6
Also see the NewsFlash project page.
Reported By:
Fixed By:
Coordinated By:
- Michael Hess of the Drupal Security Team