Vulnerabilities > Drupal > CCK Comment Reference > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-04-20 CVE-2009-1342 Cross-Site Scripting vulnerability in Drupal CCK Comment Reference 6.X/6.X1.1
Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form.
network
drupal CWE-79
4.3