Description
|
|
Two vulnerabilities have been identified in Printer, e-mail and PDF versions (module for Drupal), which could be exploited by attackers to execute arbitrary scripting code or gain knowledge of potentially sensitive information.
The first issue is caused by an input validation error when displaying the list of links in a page, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected site.
The second weakness is caused by an error in the the "Send by e-mail" sub-module that does not properly validate permissions before displaying the "Send to friend" form, which could allow attackers titles of unpublished or privleged pages.
|