CVE-2013-0324

Tomasbarej Menu Reference - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu link title.

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Details

CWE
CWE-79
Status published
Products (2)
tomasbarej/menu_reference
n/a/n/a
Published Mar 27, 2013
Tracked Since Feb 18, 2026