6.2 Medium
AI Score
Confidence
High
0.003 Low
EPSS
Percentile
65.5%
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
osvdb.org/50208
secunia.com/advisories/32904
www.securityfocus.com/bid/32491
drupal.org/node/339553
exchange.xforce.ibmcloud.com/vulnerabilities/46947