MidnightBSD

Advisories for inline_entity_form_project

CVE-2015-5507 MEDIUM

Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
inline_entity_form_project inline_entity_form 7.x-1.2
inline_entity_form_project inline_entity_form 7.x-1.3
inline_entity_form_project inline_entity_form 7.x-1.0
inline_entity_form_project inline_entity_form 7.x-1.4
inline_entity_form_project inline_entity_form 7.x-1.5
inline_entity_form_project inline_entity_form 7.x-1.1