Cross-site scripting (XSS) vulnerability in E-commerce 4.7 for Drupal before file.module 1.37.2.4 (20060812) allows remote authenticated users with the create products permission to inject arbitrary web script or HTML via unspecified vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Drupal_e-commerce_module | Drupal | 4.7 (including) | 4.7 (including) |