SA-CONTRIB-2014-034 - Professional Theme - Cross Site Scripting
Security risk:
Moderately critical
Exploitable from:
Remote
Vulnerability:
Cross Site Scripting
Description:
The theme does not sufficiently sanitize theme settings input for custom copyright information
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer themes".
Versions affected:
all 7.x releases
Solution:
Install the latest version: