Unrated severityNVD Advisory· Published Aug 31, 2015· Updated May 6, 2026
CVE-2015-6751
CVE-2015-6751
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2) activity used to categorize time tracker entries.
Affected products
4cpe:2.3:a:time_tracker_project:time_tracker:7.x-1.0:*:*:*:*:drupal:*:*+ 3 more
- cpe:2.3:a:time_tracker_project:time_tracker:7.x-1.0:*:*:*:*:drupal:*:*
- cpe:2.3:a:time_tracker_project:time_tracker:7.x-1.1:*:*:*:*:drupal:*:*
- cpe:2.3:a:time_tracker_project:time_tracker:7.x-1.2:*:*:*:*:drupal:*:*
- cpe:2.3:a:time_tracker_project:time_tracker:7.x-1.3:*:*:*:*:drupal:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.drupal.org/node/2537296nvdPatch
- www.drupal.org/node/2537866nvdPatchVendor Advisory
- cgit.drupalcode.org/time_tracker/commit/nvd
News mentions
0No linked articles in our index yet.