Lucene search

K
cveMitreCVE-2014-9346
HistoryDec 08, 2014 - 4:59 p.m.

CVE-2014-9346

2014-12-0816:59:18
CWE-79
mitre
web.nvd.nist.gov
22
cve-2014-9346
cross-site scripting
xss
drupal
hierarchical select module
nvd
security vulnerability

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

41.9%

Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for instances with Save term lineage enabled or (2) entity type fields.

Affected configurations

Nvd
Node
hierarchical_select_projecthierarchical_selectMatch6.x-3.0drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.1drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.2drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.3drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.4drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.5drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.6drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.7drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.8drupal
OR
hierarchical_select_projecthierarchical_selectMatch6.x-3.xdevdrupal
VendorProductVersionCPE
hierarchical_select_projecthierarchical_select6.x-3.0cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.0:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.1cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.1:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.2cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.2:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.3cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.3:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.4cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.4:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.5cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.5:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.6cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.6:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.7cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.7:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.8cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.8:*:*:*:*:drupal:*:*
hierarchical_select_projecthierarchical_select6.x-3.xcpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.x:dev:*:*:*:drupal:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

41.9%

Related for CVE-2014-9346