Description
|
|
Two vulnerabilities have been identified in Webform (module for Drupal), which could be exploited by attackers to execute arbitrary scripting code or gain knowledge of potentially sensitive information.
The first issue is caused by an input validation error when handling field labels, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected site.
The second weakness is caused due to the module failing to prevent a page from being cached when a default value uses token placeholders, which could lead to the disclosure of session variables to anonymous users when caching is enabled.
|