CVE-2013-1971

Jordan DE Laune Mp3 Player < 6.x-1.1 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file.

Scores

EPSS 0.0016
EPSS Percentile 36.5%

Details

CWE
CWE-79
Status published
Products (4)
jordan_de_laune/mp3_player < 6.x-1.1
jordan_de_laune/mp3_player
jordan_de_laune/mp3_player
n/a/n/a
Published Jun 25, 2013
Tracked Since Feb 18, 2026