Lucene search

K
cve[email protected]CVE-2012-5538
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-5538

2022-10-0316:15:29
CWE-79
web.nvd.nist.gov
21
cve-2012-5538
cross-site scripting
xss
filefield sources module
drupal
remote code execution
nvd

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.1%

Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has “Reference existing” source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.

Affected configurations

NVD
Node
nathan_haugfilefield_sourcesMatch6.x-1.0
OR
nathan_haugfilefield_sourcesMatch6.x-1.1
OR
nathan_haugfilefield_sourcesMatch6.x-1.2
OR
nathan_haugfilefield_sourcesMatch6.x-1.3
OR
nathan_haugfilefield_sourcesMatch6.x-1.4
OR
nathan_haugfilefield_sourcesMatch6.x-1.5
OR
nathan_haugfilefield_sourcesMatch6.x-1.xdev
OR
nathan_haugfilefield_sourcesMatch7.x-1.2beta1
OR
nathan_haugfilefield_sourcesMatch7.x-1.3
OR
nathan_haugfilefield_sourcesMatch7.x-1.4
OR
nathan_haugfilefield_sourcesMatch7.x-1.5
OR
nathan_haugfilefield_sourcesMatch7.x-1.xdev
AND
drupaldrupalMatch-

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

5.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.1%

Related for CVE-2012-5538