Drupal · Cck Tablefield Module · CVE-2010-1998
**Name of the Vulnerable Software and Affected Versions**
CCK TableField module version 6.x before 6.x-1.2
**Description**
The issue allows remote authenticated users with certain node creation or editing privileges to inject arbitrary web script or HTML via table headers, which can lead to cross-site scripting (XSS).
**Recommendations**
For CCK TableField module version 6.x before 6.x-1.2, update to version 6.x-1.2 or later to resolve the issue.