MEDIUM
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages
Published Feb 5, 2008
4.3
MEDIUMCVSS 2.0
EPSS 1.02%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.