Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42fx-xh6m-j2c4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.

The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.

EPSS

Процентиль: 53%
0.00302
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
почти 13 лет назад

The filter_titles function in the Smart Breadcrumb module 6.x-1.x before 6.x-1.3 for Drupal does not properly convert a title to plain-text, which allows remote authenticated users with create or edit node permissions to conduct cross-site scripting (XSS) attacks via the title parameter.

EPSS

Процентиль: 53%
0.00302
Низкий

Дефекты

CWE-20