Lucene search

K
cvelistMitreCVELIST:CVE-2014-5021
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2014-5021

2022-10-0316:20:42
mitre
www.cve.org
6
cve-2014-5021
cross-site scripting
drupal 6.x
drupal 7.x
form api
remote authenticated users
administer taxonomy permission
arbitrary web script
html
option group label

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

30.3%

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the “administer taxonomy” permission to inject arbitrary web script or HTML via an option group label.

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

30.3%