CVE-2008-1916

Ubercart 5.x <5.x-1.0-rc1 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-rc1 module for Drupal allow remote attackers to inject arbitrary web script or HTML via text fields intended for the (1) address and (2) order information, which are later displayed on the order view page and unspecified other administrative pages, a different vulnerability than CVE-2008-1428.

Scores

EPSS 0.0030
EPSS Percentile 52.7%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

drupal/ubercart_module

Timeline

Published Apr 23, 2008
Tracked Since Feb 18, 2026