Vendorsdanielbcool_aid6.x-1.1
Vulnerabilities

danielb denielb Cool Aid module for Drupal 6.x-1.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2012-1649
Cool Aid module before 6.x-1.9 for Drupal does not enforce access restrictions, which allows remote authenticated users with the administer coolaid permission to modify arbitrary pages via unspecified vectors.
Published 2012-09-09 · Modified
4.9EPSS 0.012
CVE-2012-1648
Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.
Published 2012-09-09 · Modified
2.1EPSS 0.011