CVE-2015-4392
https://notcve.org/view.php?id=CVE-2015-4392
Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-2.7 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to field display settings. Vulnerabilidad de XSS en el módulo Display Suite 7.x-2.7 para Drupal permite a usuarios remotos autenticados inyectar secuencias de comandos web arbitrarios o HTML a través de vectores no especificados relacionados con las configuraciones de despliegue de campos. • http://www.openwall.com/lists/oss-security/2015/04/25/6 http://www.securityfocus.com/bid/74362 https://www.drupal.org/node/2471721 https://www.drupal.org/node/2471733 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •