CVE-2010-3022
Drupal Devel <6.x-1.21 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Performance logging module in the Devel module 5.x before 5.x-1.3 and 6.x before 6.x-1.21 for Drupal allows remote authenticated users, with add url aliases and report access permissions, to inject arbitrary web script or HTML via crafted node paths in a URL.
References (7)
Scores
EPSS
0.0036
EPSS Percentile
57.8%
Classification
CWE
CWE-79
Status
published
Affected Products (25)
drupal/devel_module
< 5x-1.2
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
drupal/devel_module
... and 10 more
Timeline
Published
Aug 16, 2010
Tracked Since
Feb 18, 2026