Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.
| Software | From | Fixed in |
|---|---|---|
| steven_jones / context | - | 6.x-2.0.x |
| steven_jones / context | 6.x-2.0-beta3 | 6.x-2.0-beta3.x |
| steven_jones / context | 6.x-2.0-alpha2 | 6.x-2.0-alpha2.x |
| steven_jones / context | 6.x-2.0-rc2 | 6.x-2.0-rc2.x |
| steven_jones / context | 6.x-2.0-alpha1 | 6.x-2.0-alpha1.x |
| steven_jones / context | 6.x-2.0-beta5 | 6.x-2.0-beta5.x |
| steven_jones / context | 6.x-2.0-beta7 | 6.x-2.0-beta7.x |
| steven_jones / context | 6.x-2.0-beta2 | 6.x-2.0-beta2.x |
| steven_jones / context | 6.x-2.0-beta4 | 6.x-2.0-beta4.x |
| steven_jones / context | 6.x-2.0-beta6 | 6.x-2.0-beta6.x |
| steven_jones / context | 6.x-2.0-beta1 | 6.x-2.0-beta1.x |
| steven_jones / context | 6.x-2.0-rc1 | 6.x-2.0-rc1.x |