Showing 2 vulnerabilities on this page for Data-module

Signals CISA KEV Ransomware Nuclei
Drupal vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Drupal SQL Injection vulnerability

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

CWE-89Jan 14, 2020
CVSS9.8v3.1EPSS1.07%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Drupal Cross-Site Scripting vulnerability

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

CWE-79Jan 14, 2020
CVSS6.1v3.1EPSS1.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX