Back

LOW

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name

Published Mar 19, 2013

Description

Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Mar 19, 2013
Updated Sep 16, 2024
Reserved Dec 6, 2012

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 16, 2026

Red Hat

No data

ENISA EUVD

Assigner redhat
Published Mar 19, 2013
Updated Sep 16, 2024

GitHub

No data