3.5
CVSSv2

CVE-2015-4357

Published: 15/06/2015 Updated: 30/06/2015
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Webform module prior to 6.x-3.22, 7.x-3.x prior to 7.x-3.22, and 7.x-4.x prior to 7.x-4.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title, which is used as the default title of a webform block.

Vulnerable Product Search on Vulmon Subscribe to Product

webform project webform 7.x-3.0

webform project webform 7.x-3.1

webform project webform 7.x-3.10

webform project webform 7.x-3.11

webform project webform 7.x-4.3

webform project webform 7.x-3.9

webform project webform 7.x-3.8

webform project webform 7.x-3.7

webform project webform 7.x-3.20

webform project webform 7.x-3.21

webform project webform 7.x-3.19

webform project webform 7.x-3.18

webform project webform 7.x-4.0

webform project webform 7.x-4.2

webform project webform 7.x-3.6

webform project webform 7.x-3.4

webform project webform 7.x-3.13

webform project webform 7.x-3.15

webform project webform 7.x-3.16

webform project webform 7.x-4.1

webform project webform 7.x-3.5

webform project webform 7.x-3.3

webform project webform 7.x-3.12

webform project webform 7.x-3.14

webform project webform 7.x-3.2

webform project webform 7.x-3.17

webform project webform