Lucene search

K
cvelistMitreCVELIST:CVE-2010-1958
HistoryJun 21, 2010 - 7:00 p.m.

CVE-2010-1958

2010-06-2119:00:00
mitre
www.cve.org

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.5%

Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and β€˜Path to File’ or β€˜URL to File’ display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.5%

Related for CVELIST:CVE-2010-1958