Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2725

Опубликовано: 27 июн. 2012
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:authoring_html:6.x-1.0:*:*:*:*:*:*:*:*
cpe:2.3:a:drupal:drupal:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00155
Низкий

3.5 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
около 3 лет назад

classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks.

EPSS

Процентиль: 37%
0.00155
Низкий

3.5 Low

CVSS2

Дефекты

CWE-264