XSS Vulnerability in Ubercart for Drupal
CVE-2008-1978

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
27 April 2008

Summary

A cross-site scripting vulnerability exists in the Ubercart 5.x module for Drupal versions prior to 5.x-1.0 rc3. The flaw allows remote authenticated users to inject arbitrary web scripts or HTML into node titles associated with unspecified product features. This vulnerability represents a distinct attack vector when compared to similar issues documented in related vulnerabilities.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.