CVE-2014-8075
Drupal Tribune 6.x-1.x and 7.x-3.x - Authenticated Stored Cross-Site Scripting via Node Title
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65236
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90830
Vendor Advisory x_refsource_misc
https://www.drupal.org/node/2184845
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/102655
Scores
EPSS
0.0015
EPSS Percentile
35.4%
Details
CWE
CWE-79
Status
published
Products (3)
drupal/tribune
6.x-1.2
drupal/tribune
6.x-1.13
drupal/tribune
7.x-3.0 beta4
Published
Oct 09, 2014
Tracked Since
Feb 18, 2026