VendorsInvoice Projectinvoice6.x-1.1
Vulnerabilities

Invoice Project Invoice 6.x-1.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2015-4382
Multiple cross-site request forgery (CSRF) vulnerabilities in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) create, (2) delete, or (3) alter invoices via unspecified vectors.
Published 2015-06-15 · Modified
6.8EPSS 0.006
CVE-2015-4381
Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "Administer own invoices" permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the "Invoice" content type.
Published 2015-06-15 · Modified
3.5EPSS 0.009