Lucene search

K
cvelistMitreCVELIST:CVE-2010-2158
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-2158

2022-10-0316:21:07
mitre
www.cve.org
1
cve-2010-2158
cross-site scripting
storm module
drupal
remote authenticated
web script
html

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.3%

Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.3%

Related for CVELIST:CVE-2010-2158