Lucene search

K
cveMitreCVE-2014-8378
HistoryOct 21, 2014 - 3:55 p.m.

CVE-2014-8378

2014-10-2115:55:08
CWE-79
mitre
web.nvd.nist.gov
24
cve-2014-8378
cross-site scripting
xss vulnerability
tablefield module
security vulnerability
nvd
admin permissions
entity edit form

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

44.6%

Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the “administer content types” or “administer taxonomy” permission to inject arbitrary web script or HTML via vectors related to the field help text in an entity edit form.

Affected configurations

Nvd
Node
tablefield_projecttablefieldMatch7.x-2.0drupal
OR
tablefield_projecttablefieldMatch7.x-2.1drupal
OR
tablefield_projecttablefieldMatch7.x-2.2drupal
VendorProductVersionCPE
tablefield_projecttablefield7.x-2.0cpe:2.3:a:tablefield_project:tablefield:7.x-2.0:*:*:*:*:drupal:*:*
tablefield_projecttablefield7.x-2.1cpe:2.3:a:tablefield_project:tablefield:7.x-2.1:*:*:*:*:drupal:*:*
tablefield_projecttablefield7.x-2.2cpe:2.3:a:tablefield_project:tablefield:7.x-2.2:*:*:*:*:drupal:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

44.6%

Related for CVE-2014-8378