Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gw2-26w5-pcm6

Опубликовано: 21 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

EPSS

Процентиль: 67%
0.00542
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 5 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
nvd
больше 5 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.

CVSS3: 4.8
debian
больше 5 лет назад

Locale module and dependent contributed modules in Drupal 6.x before 6 ...

EPSS

Процентиль: 67%
0.00542
Низкий