Drupal Easy Social Module Cross Site Scripting Vulnerability

The Easy Social module for Drupal is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.

Easy Social 7.x-2.x versions prior to 7.x-2.11 are vulnerable.


Privacy Statement
Copyright 2010, SecurityFocus