Description
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
Remediation
References
Related Vulnerabilities
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-15929)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3488)
MySQL CVE-2020-2895 Vulnerability (CVE-2020-2895)
WordPress Plugin All-in-One WP Migration Multiple Cross-Site Request Forgery Vulnerabilities (7.1)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0304)