First published: Tue Feb 05 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Project Issue Tracking Module | =4.7 | |
Drupal Project Issue Tracking Module | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0576 has a moderate severity level due to its cross-site scripting (XSS) vulnerability.
To fix CVE-2008-0576, upgrade to the latest version of the Project Issue Tracking module that addresses this vulnerability.
CVE-2008-0576 affects the Project Issue Tracking module versions 4.7.x-2.6 and earlier, and 5.x-2.x-dev before 20080130.
CVE-2008-0576 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML.
Users and administrators of affected Drupal installations utilizing the Project Issue Tracking module are impacted by CVE-2008-0576.