CVE-2010-0697

Drupal iTweak Upload module <6.x-1.2/<6.x-2.3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.

Scores

EPSS 0.0020
EPSS Percentile 41.7%

Classification

CWE
CWE-79
Status published

Affected Products (9)

ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
ilya_ivanchenko/itweak_upload
n/a/n/a

Timeline

Published Feb 23, 2010
Tracked Since Feb 18, 2026