Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitrary web script or HTML via unspecified vectors.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| inline_entity_form_project | inline_entity_form | 7.x-1.2 |
| inline_entity_form_project | inline_entity_form | 7.x-1.3 |
| inline_entity_form_project | inline_entity_form | 7.x-1.0 |
| inline_entity_form_project | inline_entity_form | 7.x-1.4 |
| inline_entity_form_project | inline_entity_form | 7.x-1.5 |
| inline_entity_form_project | inline_entity_form | 7.x-1.1 |