MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title
Published Jul 6, 2015
4.3
MEDIUMCVSS 2.0
EPSS 1.17%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.