CVE-2015-4346

Cross-site scripting (XSS) vulnerability in the SMS Framework module 6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to message previews.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sms_framework_project:sms_framework:6.x-1.0:*:*:*:*:drupal:*:*
cpe:2.3:a:sms_framework_project:sms_framework:6.x-2.x-dev:*:*:*:*:drupal:*:*
cpe:2.3:a:sms_framework_project:sms_framework:6.x-2.0-alpha1:*:*:*:*:drupal:*:*
cpe:2.3:a:sms_framework_project:sms_framework:6.x-1.1:*:*:*:*:drupal:*:*

Information

Published : 2015-06-15 07:59

Updated : 2015-06-30 06:14


NVD link : CVE-2015-4346

Mitre link : CVE-2015-4346


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

sms_framework_project

  • sms_framework