CVE-2010-2010

Chaos Tool Suite Ctools - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script or HTML via a node title.

Scores

EPSS 0.0031
EPSS Percentile 53.8%

Classification

CWE
CWE-79
Status published

Affected Products (14)

chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
n/a/n/a

Timeline

Published May 21, 2010
Tracked Since Feb 18, 2026