An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1xcDhxLWd3ZjUtaHFoMs0_SQ

Moderate CVSS: 6.1 EPSS: 0.00528% (0.66502 Percentile) EPSS:

Drupal Cross-Site Scripting vulnerability

Affected Packages Affected Versions Fixed Versions
packagist:drupal/core = 6.20 No known fixed version
770 Dependent packages
5,293 Dependent repositories
60,005,864 Downloads total

Affected Version Ranges

All affected versions

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

References: