Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq73-c7h9-wr72

Опубликовано: 21 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

Drupal 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

EPSS

Процентиль: 70%
0.00673
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
nvd
больше 5 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.

CVSS3: 6.1
debian
больше 5 лет назад

Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output du ...

EPSS

Процентиль: 70%
0.00673
Низкий

Дефекты

CWE-79