CVE-2015-3361
21.04.2015, 16:59
Cross-site scripting (XSS) vulnerability in the Linkit module before 7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when the node search plugin is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a node title.
Vendor | Product | Version |
---|---|---|
linkit_project | linkit | 7.x-1.0 ≤ 𝑥 < 7.x-2.7 |
linkit_project | linkit | 7.x-3.0 ≤ 𝑥 < 7.x-3.3 |
𝑥
= Vulnerable software versions
References