Lucene search

K
cvelistMitreCVELIST:CVE-2014-7980
HistoryOct 08, 2014 - 6:00 p.m.

CVE-2014-7980

2014-10-0818:00:00
mitre
www.cve.org
5
cross-site scripting
zen theme
drupal
remote authenticated users
administer themes permission

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

45.1%

Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the “administer themes” permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

45.1%

Related for CVELIST:CVE-2014-7980