Lucene search

K
nvd[email protected]NVD:CVE-2013-4447
HistoryNov 01, 2013 - 3:55 p.m.

CVE-2013-4447

2013-11-0115:55:03
CWE-79
web.nvd.nist.gov
4

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.003

Percentile

68.6%

Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.

Affected configurations

Nvd
Node
md-systemssimplenewsMatch6.x-1.0-drupal
OR
md-systemssimplenewsMatch6.x-1.0beta1drupal
OR
md-systemssimplenewsMatch6.x-1.0beta2drupal
OR
md-systemssimplenewsMatch6.x-1.0beta3drupal
OR
md-systemssimplenewsMatch6.x-1.0beta4drupal
OR
md-systemssimplenewsMatch6.x-1.0beta5drupal
OR
md-systemssimplenewsMatch6.x-1.0rc1drupal
OR
md-systemssimplenewsMatch6.x-1.0rc2drupal
OR
md-systemssimplenewsMatch6.x-1.0rc3drupal
OR
md-systemssimplenewsMatch6.x-1.0rc4drupal
OR
md-systemssimplenewsMatch6.x-1.0rc5drupal
OR
md-systemssimplenewsMatch6.x-1.0rc6drupal
OR
md-systemssimplenewsMatch6.x-1.1-drupal
OR
md-systemssimplenewsMatch6.x-1.2-drupal
OR
md-systemssimplenewsMatch6.x-1.3-drupal
OR
md-systemssimplenewsMatch6.x-1.4-drupal
OR
md-systemssimplenewsMatch6.x-1.xdevdrupal
OR
md-systemssimplenewsMatch7.x-1.0-drupal
OR
md-systemssimplenewsMatch7.x-1.0alpha1drupal
OR
md-systemssimplenewsMatch7.x-1.0alpha2drupal
OR
md-systemssimplenewsMatch7.x-1.0beta1drupal
OR
md-systemssimplenewsMatch7.x-1.0beta2drupal
OR
md-systemssimplenewsMatch7.x-1.0rc1drupal
OR
md-systemssimplenewsMatch7.x-1.xdevdrupal
VendorProductVersionCPE
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:-:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta1:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta2:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta3:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta4:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:beta5:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc1:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc2:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc3:*:*:*:drupal:*:*
md-systemssimplenews6.x-1.0cpe:2.3:a:md-systems:simplenews:6.x-1.0:rc4:*:*:*:drupal:*:*
Rows per page:
1-10 of 241

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.003

Percentile

68.6%

Related for NVD:CVE-2013-4447