Description
|
|
Two vulnerabilities have been identified in Talk (module for Drupal), which could be exploited to gain knowledge of sensitive information or execute scripting code.
The first issue is caused by an input validation error when processing and displaying node titles, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
The second vulnerability is caused by an error when displaying comments, which could be exploited by attackers to bypass security restrictions and disclose sensitive information.
|