CVE-2015-4381 Information

Description

Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the \Administer own invoices\ permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the \Invoice\ content type.

Reference

http://www.openwall.com/lists/oss-security/2015/04/25/6 http://www.securityfocus.com/bid/74345 https://www.drupal.org/node/2459337 https://www.drupal.org/node/2474135 https://www.drupal.org/node/2474139

Share on: