Lucene search

K
nvd[email protected]NVD:CVE-2014-8378
HistoryOct 21, 2014 - 3:55 p.m.

CVE-2014-8378

2014-10-2115:55:08
CWE-79
web.nvd.nist.gov
2

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

44.6%

Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the “administer content types” or “administer taxonomy” permission to inject arbitrary web script or HTML via vectors related to the field help text in an entity edit form.

Affected configurations

Nvd
Node
tablefield_projecttablefieldMatch7.x-2.0drupal
OR
tablefield_projecttablefieldMatch7.x-2.1drupal
OR
tablefield_projecttablefieldMatch7.x-2.2drupal
VendorProductVersionCPE
tablefield_projecttablefield7.x-2.0cpe:2.3:a:tablefield_project:tablefield:7.x-2.0:*:*:*:*:drupal:*:*
tablefield_projecttablefield7.x-2.1cpe:2.3:a:tablefield_project:tablefield:7.x-2.1:*:*:*:*:drupal:*:*
tablefield_projecttablefield7.x-2.2cpe:2.3:a:tablefield_project:tablefield:7.x-2.2:*:*:*:*:drupal:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

44.6%

Related for NVD:CVE-2014-8378