Project: 
Date: 
2019-August-14
Vulnerability: 
Cross site scripting
Description: 

The Scroll To Top module enables you to have an animated scroll to top link in the bottom of the node.

The module does not sufficiently filter configuration text leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer scroll to top".

Solution: 

Install the latest version of the module.

Also see the scroll to top project page.

Coordinated By: