Drupal · Ubercart Webform Integration · CVE-2015-4354
**Name of the Vulnerable Software and Affected Versions**
Ubercart Webform Integration module versions prior to 6.x-1.8
Ubercart Webform Integration module versions prior to 7.x-2.4
**Description**
The issue allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors, which is a cross-site scripting (XSS) vulnerability.
**Recommendations**
For Ubercart Webform Integration module versions prior to 6.x-1.8, update to version 6.x-1.8 or later.
For Ubercart Webform Integration module versions prior to 7.x-2.4, update to version 7.x-2.4 or later.