Skip to main content

Vendor/product archive

janrain / rpx CVEs

Beta · best-effort

2 CVEs tagged to janrain / rpx0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2012-2296

Published Jul 25, 2012

The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores user profile data from Engage in session tables, which might…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0771

Published Feb 4, 2011

The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1