XSS Vulnerability in Ubercart Webform Integration Module for Drupal
CVE-2015-4354

Currently unrated

What is CVE-2015-4354?

The Ubercart Webform Integration module for Drupal is susceptible to a cross-site scripting (XSS) vulnerability. This flaw allows remote authenticated users with certain permissions to execute arbitrary web scripts or inject HTML, potentially compromising the site's integrity. The vulnerability exists in versions prior to 6.x-1.8 and 7.x-2.4, and it poses a significant risk where an attacker can manipulate the web application by exploiting this weakness.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.