Vulnerabilities > Password Policy Project > Password Policy > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-06-15 | CVE-2015-4387 | Cross-site Scripting vulnerability in Password Policy Project Password Policy Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source. | 2.6 |