Unrated severityNVD Advisory· Published Apr 8, 2010· Updated Apr 29, 2026
CVE-2010-1303
CVE-2010-1303
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Filter module 6.x before 6.x-1.1 for Drupal allow remote authenticated users, with administer taxonomy permissions or create node permissions when free tagging is enabled, to inject arbitrary web script or HTML via vocabulary (1) names, (2) terms, and (3) filter menus.
Affected products
2cpe:2.3:a:jim_berry:taxonomy_filter:6.x-1.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jim_berry:taxonomy_filter:6.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:jim_berry:taxonomy_filter:6.x-1.x-dev:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- drupal.org/node/622096nvdPatch
- drupal.org/node/758756nvdPatchVendor Advisory
- secunia.com/advisories/39220nvdVendor Advisory
- www.osvdb.org/63425nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/57445nvd
News mentions
0No linked articles in our index yet.