Drupal : Lingotek Cross-Site scripting vulnerability

source
Version/Dependency
Developer Link
Severity
Information At A Glance
 
drupal.org/node/1394220
  6.xx drupal.org/node/1394412
critical

 

 

 

Summary:

The Lingotek module is vulnerable to a cross-site scripting vulnerability.

The vulnerability  is limited to those with roles that have permission to edit or create content types.

What do I do to fix this?

Update the Lingotek module for Drupal 6.x, to latest – please visit  Lingotek 6.x-1.40 for more information.

 

Reported by: Ezra Barnett Gildesgame