First published: Fri Aug 25 2006(Updated: )
Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the "create products" permission to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal E-commerce Module | =4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4360 is considered a medium severity vulnerability due to its potential impact on users' data and security.
To fix CVE-2006-4360, update the Drupal E-commerce module to version 4.7 or later that addresses this vulnerability.
CVE-2006-4360 affects remote authenticated users with the "create products" permission on Drupal E-commerce 4.7 before file.module 1.37.2.4.
CVE-2006-4360 facilitates cross-site scripting (XSS) attacks allowing injection of arbitrary web scripts or HTML.
While CVE-2006-4360 is an older vulnerability, systems still running affected versions of Drupal E-commerce are at risk if not updated.