Drupal 7 core’s Overlay module doesn’t safely handle user input, leading to reflected cross-site scripting under certain circumstances.
Only sites with the Overlay module enabled are affected by this vulnerability.
This vulnerability affects the following application versions:
- Drupal 7.0
- Drupal 7.1
- Drupal 7.2
- Drupal 7.3
- Drupal 7.4
- Drupal 7.5
- Drupal 7.6
- Drupal 7.7
- Drupal 7.8
- Drupal 7.9
- Drupal 7.10
- Drupal 7.11
- Drupal 7.12
- Drupal 7.13
- Drupal 7.14
- Drupal 7.15
- Drupal 7.16
- Drupal 7.17
- Drupal 7.18
- Drupal 7.19
- Drupal 7.20
- Drupal 7.21
- Drupal 7.22
- Drupal 7.23
- Drupal 7.24
- Drupal 7.25
- Drupal 7.26
- Drupal 7.27
- Drupal 7.28
- Drupal 7.29
- Drupal 7.30
- Drupal 7.31
- Drupal 7.32
- Drupal 7.33
- Drupal 7.34
- Drupal 7.35
- Drupal 7.36
- Drupal 7.37
- Drupal 7.38
- Drupal 7.39
- Drupal 7.40
- Drupal 7.41
- Drupal 7.42
- Drupal 7.43
- Drupal 7.44
- Drupal 7.50
- Drupal 7.51
- Drupal 7.52
- Drupal 7.53
- Drupal 7.54
- Drupal 7.55
- Drupal 7.56
- Drupal 7.57
- Drupal 7.58
- Drupal 7.59
- Drupal 7.60
- Drupal 7.61
- Drupal 7.62
- Drupal 7.63
- Drupal 7.64
- Drupal 7.65
- Drupal 7.66
- Drupal 7.67
- Drupal 7.68
- Drupal 7.69
- Drupal 7.70
- Drupal 7.71
- Drupal 7.72
- Drupal 7.73
- Drupal 7.74
- Drupal 7.75
- Drupal 7.76
- Drupal 7.77
- Drupal 7.78
- Drupal 7.79
- Drupal 7.80
- Drupal 7.81
- Drupal 7.82
- Drupal 7.83
- Drupal 7.84
- Drupal 7.85
- Drupal 7.86
- Drupal 7.87
- Drupal 7.88
- Drupal 7.89
- Drupal 7.90
- Drupal 7.91
- Drupal 7.92
- Drupal 7.93
- Drupal 7.94
- Drupal 7.95
- Drupal 7.96
- Drupal 7.97
- Drupal 7.98
- Drupal 7.99
- Drupal 7.100
- Drupal 7.101