CVE-2014-8075

Drupal Tribune 6.x-1.x and 7.x-3.x - Authenticated Stored Cross-Site Scripting via Node Title

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65236
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90830
Vendor Advisory x_refsource_misc
https://www.drupal.org/node/2184845
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102655

Scores

EPSS 0.0015
EPSS Percentile 35.4%

Details

CWE
CWE-79
Status published
Products (3)
drupal/tribune 6.x-1.2
drupal/tribune 6.x-1.13
drupal/tribune 7.x-3.0 beta4
Published Oct 09, 2014
Tracked Since Feb 18, 2026