VYPR

Navigate

by Navigate Project

CVEs (2)

  • CVE-2015-5500Aug 18, 2015
    risk 0.00cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-5499Aug 18, 2015
    risk 0.00cvss epss 0.00

    The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveraging the "navigate view" permission.