Total vulnerabilities in the database
Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comment field.
Software | From | Fixed in |
---|---|---|
john_vandyk / workflow | 5.x-2.0 | 5.x-2.0.x |
john_vandyk / workflow | 5.x-2.1 | 5.x-2.1.x |
john_vandyk / workflow | 5.x-2.2 | 5.x-2.2.x |
john_vandyk / workflow | 5.x-2.3 | 5.x-2.3.x |
john_vandyk / workflow | 5.x-2.4 | 5.x-2.4.x |
john_vandyk / workflow | 5.x-2.5 | 5.x-2.5.x |
john_vandyk / workflow | 5.x-2.x-dev | 5.x-2.x-dev.x |
john_vandyk / workflow | 6.x-1.0-beta1 | 6.x-1.0-beta1.x |
john_vandyk / workflow | 6.x-1.0-rc3 | 6.x-1.0-rc3.x |
john_vandyk / workflow | 6.x-1.0-rc1 | 6.x-1.0-rc1.x |
john_vandyk / workflow | 6.x-1.0 | 6.x-1.0.x |
john_vandyk / workflow | 6.x-1.0-beta2 | 6.x-1.0-beta2.x |
john_vandyk / workflow | 6.x-1.0-rc4 | 6.x-1.0-rc4.x |
john_vandyk / workflow | 6.x-1.1 | 6.x-1.1.x |
john_vandyk / workflow | 6.x-1.2 | 6.x-1.2.x |
john_vandyk / workflow | 6.x-1.3 | 6.x-1.3.x |
john_vandyk / workflow | 6.x-1.4 | 6.x-1.4.x |
john_vandyk / workflow | 6.x-1.x-dev | 6.x-1.x-dev.x |