XSS Vulnerability in Ubercart for Drupal
CVE-2008-1978
Currently unrated
Summary
A cross-site scripting vulnerability exists in the Ubercart 5.x module for Drupal versions prior to 5.x-1.0 rc3. The flaw allows remote authenticated users to inject arbitrary web scripts or HTML into node titles associated with unspecified product features. This vulnerability represents a distinct attack vector when compared to similar issues documented in related vulnerabilities.
References
Timeline
Vulnerability published
Vulnerability Reserved