CVE-2015-4381 Information
Feb 14, 2021
cve
Description
Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the \Administer own invoices\ permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the \Invoice\ content type.
Reference
http://www.openwall.com/lists/oss-security/2015/04/25/6 http://www.securityfocus.com/bid/74345 https://www.drupal.org/node/2459337 https://www.drupal.org/node/2474135 https://www.drupal.org/node/2474139
Share on: