Vulnerabilities > Current Search Links Project > Current Search Links

DATE CVE VULNERABILITY TITLE RISK
2015-06-15 CVE-2015-4388 Cross-site Scripting vulnerability in Current Search Links Project Current Search Links 7.X1.0/7.X1.Xdev
Cross-site scripting (XSS) vulnerability in the Current Search Links module 7.x-1.x before 7.x-1.1 for Drupal, when the "Append the keywords passed by the user to the list" option is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted search query.
network
high complexity
current-search-links-project CWE-79
2.6