Lucene search

K
cve[email protected]CVE-2013-4229
HistoryAug 21, 2013 - 2:55 p.m.

CVE-2013-4229

2013-08-2114:55:07
CWE-79
web.nvd.nist.gov
14
cve-2013-4229
cross-site scripting
xss
vulnerability
monster menus module
drupal
web security
html injection

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.1%

Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated users with permissions to add pages to inject arbitrary web script or HTML via a title in the page settings.

Affected configurations

NVD
Node
monster_menus_module_projectmonster_menusMatch7.x-1.0
OR
monster_menus_module_projectmonster_menusMatch7.x-1.1
OR
monster_menus_module_projectmonster_menusMatch7.x-1.2
OR
monster_menus_module_projectmonster_menusMatch7.x-1.3
OR
monster_menus_module_projectmonster_menusMatch7.x-1.4
OR
monster_menus_module_projectmonster_menusMatch7.x-1.5
OR
monster_menus_module_projectmonster_menusMatch7.x-1.6
OR
monster_menus_module_projectmonster_menusMatch7.x-1.7
OR
monster_menus_module_projectmonster_menusMatch7.x-1.8
OR
monster_menus_module_projectmonster_menusMatch7.x-1.9
OR
monster_menus_module_projectmonster_menusMatch7.x-1.10
OR
monster_menus_module_projectmonster_menusMatch7.x-1.11
OR
monster_menus_module_projectmonster_menusMatch7.x-1.xdev
AND
drupaldrupalMatch-

2.1 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:S/C:N/I:P/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.1%

Related for CVE-2013-4229