Still on Drupal 7? Security support for Drupal 7 ended on 5 January 2025. Please visit our Drupal 7 End of Life resources page to review all of your options.
Version 6.x-1.5
---------------
When the user logs out of Drupal, s/he also is logged out of phpFreeChat (a phpFreeChat /quit command is issued programmatically when the Drupal logout event occurs).
When a webform component is used as the "To" address or addresses for sending an e-mail, the name of the component is not sufficiently sanitized when it is displayed in the list of e-mail settings, leading to a Cross Site Scripting (XSS) vulnerability.