Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the create products permission to inject arbitrary web script or HTML via unspecified vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Drupal_e-commerce_module | Drupal | 4.7 (including) | 4.7 (including) |