Cross-Site Scripting Flaw in Public Download Count Module for Drupal
CVE-2015-3389
Currently unrated
Key Information:
- Status
- Vendor
- CVE Published:
- 21 April 2015
What is CVE-2015-3389?
The XSS vulnerability in the Download Count report page of the Public Download Count module for Drupal allows remote authenticated users to inject arbitrary web scripts or HTML. This can potentially lead to unauthorized actions being performed on behalf of the user, along with the exposure of sensitive information. The vulnerability affects the module in versions 7.x-1.x-dev and earlier, highlighting the importance of securing web applications against script injection attacks.
