Lucene search

K
cvelistMitreCVELIST:CVE-2014-8077
HistoryOct 09, 2014 - 2:00 p.m.

CVE-2014-8077

2014-10-0914:00:00
mitre
www.cve.org

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.2%

Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the β€œadminister themes” permission to inject arbitrary web script or HTML via vectors related to font family CSS property.

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.2%

Related for CVELIST:CVE-2014-8077