Drupal Ajax System Cross Site Scripting Vulnerability

Drupal is prone to a cross-site scripting vulnerability.

An attacker can exploit this issue to execute arbitrary script code in the context of the vulnerable site, potentially allowing the attacker to steal cookie-based authentication credentials.

Drupal core 7.x versions prior to 7.39 are vulnerable.


