1 results (0.019 seconds)

CVSS: 4.3EPSS: 0%CPEs: 23EXPL: 0

Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the Name field in an invitation. Una vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados en el módulo de Drupal "Temporary Invitation" v5.X antes de v5.x-2.3 permite a atacantes remotos inyectar HTML o scripts web a través del campo Name en una invitación. • http://drupal.org/node/623018 http://drupal.org/node/623526 http://osvdb.org/59679 http://secunia.com/advisories/37286 http://www.securityfocus.com/bid/37072 https://exchange.xforce.ibmcloud.com/vulnerabilities/54148 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •