CVE

Id
72466  
CVE No.
CVE-2014-5169  
Status
Candidate  
Description
Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title.  
Phase
Assigned (20140731)  
Votes
None (candidate not yet proposed)  
Comments