Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx48-g6pf-jvc9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

EPSS

Процентиль: 68%
0.00583
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
почти 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

nvd
почти 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.

debian
почти 17 лет назад

The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before ...

EPSS

Процентиль: 68%
0.00583
Низкий

Дефекты

CWE-79