Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Scheepers_de_bruin Category Tokens模块跨站脚本攻击漏洞
Vulnerability Description
Drupal的Category Tokens模块6.x-1.1之前的6.x版本中存在跨站脚本攻击漏洞。具有管理分类许可的远程认证用户可通过编辑或创建词汇名称注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A