Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content creation and activity stream messages.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8747
Reference (s):
- BID:65524
- URL: http://www.securityfocus.com/bid/65524
- https://www.drupal.org/node/2194777
- https://www.drupal.org/node/2194877
- OSVDB:103288

