Drupal · Ubercart Webform Checkout Pane · CVE-2015-4384
**Name of the Vulnerable Software and Affected Versions**
Ubercart Webform Checkout Pane module versions 6.x-3.x before 6.x-3.10
Ubercart Webform Checkout Pane module versions 7.x-3.x before 7.x-3.11
**Description**
The issue is related to a cross-site scripting (XSS) vulnerability. This allows remote authenticated users with certain permissions to inject arbitrary web script or HTML.
**Recommendations**
For Ubercart Webform Checkout Pane module versions 6.x-3.x before 6.x-3.10, update to version 6.x-3.10 or later.
For Ubercart Webform Checkout Pane module versions 7.x-3.x before 7.x-3.11, update to version 7.x-3.11 or later.