Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2014-5021
HistoryJul 22, 2014 - 2:55 p.m.

CVE-2014-5021

2014-07-2214:55:00
Debian Security Bug Tracker
security-tracker.debian.org
22

EPSS

0.001

Percentile

30.3%

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the “administer taxonomy” permission to inject arbitrary web script or HTML via an option group label.

OSVersionArchitecturePackageVersionFilename
Debian9alldrupal7< 7.52-2+deb9u11drupal7_7.52-2+deb9u11_all.deb

EPSS

0.001

Percentile

30.3%