Описание
Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:commerce_balanced_payments_project:commerce_balanced_payments:7.x-1.2:*:*:*:*:drupal:*:*
EPSS
Процентиль: 43%
0.00209
Низкий
3.5 Low
CVSS2
Дефекты
CWE-79
EPSS
Процентиль: 43%
0.00209
Низкий
3.5 Low
CVSS2
Дефекты
CWE-79