
CVE-2025-48920 – etracker - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-074
https://notcve.org/view.php?id=CVE-2025-48920
13 Jun 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker allows Cross-Site Scripting (XSS).This issue affects etracker: from 0.0.0 before 3.1.0. • https://www.drupal.org/sa-contrib-2025-074 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2010-1543
https://notcve.org/view.php?id=CVE-2010-1543
26 Apr 2010 — Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo eTracker anterior v6.x-1.2 para Drupal permite a atacantes remotos inyectar código web o HTML de su elección por añadiéndolos a una cadena manipulada en una URL asociada de su elección... • http://drupal.org/node/731018 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •