Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2wg-8h29-874v

Опубликовано: 01 апр. 2025
Источник: github
Github: Прошло ревью
CVSS4: 1.3
CVSS3: 6.1

Описание

Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS). This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.

Пакеты

Наименование

drupal/link_field_display_mode_formatter

composer
Затронутые версииВерсия исправления

< 1.6.0

1.6.0

EPSS

Процентиль: 4%
0.0002
Низкий

1.3 Low

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

redhat
6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.

CVSS3: 6.1
nvd
6 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.

EPSS

Процентиль: 4%
0.0002
Низкий

1.3 Low

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79