Vulnerabilities > Erik Webb

DATE CVE VULNERABILITY TITLE RISK
2012-09-20 CVE-2012-1632 Cross-Site Scripting vulnerability in Erik Webb Password Policy
Cross-site scripting (XSS) vulnerability in password_policy.admin.inc in the Password Policy module before 6.x-1.4 and 7.x-1.0 beta3 for Drupal allows remote authenticated users with administer policies permissions to inject arbitrary web script or HTML via the name parameter.
network
high complexity
erik-webb drupal CWE-79
2.1