CVE-2007-4363: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when using (1) the plain formatter or (2) the autocomplete text field widget without Views.module.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4363?
CVE-2007-4363 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-4363?
To fix CVE-2007-4363, upgrade to the latest version of the Drupal Content Construction Kit that is not vulnerable.
What systems are affected by CVE-2007-4363?
CVE-2007-4363 affects Drupal Content Construction Kit versions earlier than 4.7.x-1.6 and 5.x prior to 5.x-1.6.
What type of vulnerability is CVE-2007-4363?
CVE-2007-4363 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Can CVE-2007-4363 be exploited remotely?
Yes, CVE-2007-4363 can be exploited remotely by attackers to execute malicious scripts on users' browsers.