Launchpad.net

CVE 2016-7571

Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.

See the CVE page on Mitre.org for more details.

References