5.6 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
44.7%
Cross-site scripting (XSS) vulnerability in the Contact Save module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the access site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.
drupalcode.org/project/contact_save.git/commit/0654894
osvdb.org/80669
secunia.com/advisories/48619
www.openwall.com/lists/oss-security/2012/04/07/1
www.securityfocus.com/bid/52787
drupal.org/node/1506438
drupal.org/node/953788
exchange.xforce.ibmcloud.com/vulnerabilities/74515