CVE-2007-0534

medium

Description

Multiple cross-site scripting (XSS) vulnerabilities in the (1) Project issue tracking 4.7.0 through 5.x before 20070123 and (2) Project 4.6.0 through 5.x before 20070123 modules for Drupal allow remote authenticated users to inject arbitrary web script or HTML via (a) certain "fields on project nodes" or (b) "certain project-specific settings regarding issue tracking."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/31728

http://www.vupen.com/english/advisories/2007/0312

http://www.securityfocus.com/bid/22224

http://secunia.com/advisories/23908

http://osvdb.org/32133

http://drupal.org/node/112146

Details

Source: Mitre, NVD

Published: 2007-01-26

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00475