CVE-2009-3648

Apsivam Service Links - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names.

Scores

EPSS 0.0011
EPSS Percentile 29.3%

Classification

CWE
CWE-79
Status published

Affected Products (2)

apsivam/service_links
n/a/n/a

Timeline

Published Oct 09, 2009
Tracked Since Feb 18, 2026