Lucene search

K
cvelistMitreCVELIST:CVE-2014-7869
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2014-7869

2022-10-0316:20:34
mitre
www.cve.org
2
cve-2014-7869
cross-site scripting
configuration ui
context form alteration
drupal
remote authenticated users
administer contexts permission
arbitrary web script
html
unspecified vectors

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.3%

Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the β€œadminister contexts” permission to inject arbitrary web script or HTML via unspecified vectors.

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.3%

Related for CVELIST:CVE-2014-7869