2.1
CVE-2013-4380
- EPSS 0.23%
- Veröffentlicht 20.05.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediafront ≫ Mediafront Version6.x-1.0
Mediafront ≫ Mediafront Version6.x-1.0 Updatebeta1
Mediafront ≫ Mediafront Version6.x-1.0 Updatebeta2
Mediafront ≫ Mediafront Version6.x-1.0 Updatebeta4
Mediafront ≫ Mediafront Version6.x-1.0 Updatebeta5
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc1
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc2
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc3
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc4
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc5
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc6
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc7
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc8
Mediafront ≫ Mediafront Version6.x-1.0 Updaterc9
Mediafront ≫ Mediafront Version6.x-1.1
Mediafront ≫ Mediafront Version6.x-1.2
Mediafront ≫ Mediafront Version6.x-1.3
Mediafront ≫ Mediafront Version6.x-1.5
Mediafront ≫ Mediafront Version6.x-1.x Updatedev
Mediafront ≫ Mediafront Version7.x-2.0 Update-
Mediafront ≫ Mediafront Version7.x-2.0 Updatealpha1
Mediafront ≫ Mediafront Version7.x-2.0 Updatealpha2
Mediafront ≫ Mediafront Version7.x-2.0 Updatealpha3
Mediafront ≫ Mediafront Version7.x-2.0 Updatealpha4
Mediafront ≫ Mediafront Version7.x-2.0 Updatealpha5
Mediafront ≫ Mediafront Version7.x-2.0 Updatebeta1
Mediafront ≫ Mediafront Version7.x-2.0 Updatebeta2
Mediafront ≫ Mediafront Version7.x-2.0 Updatebeta4
Mediafront ≫ Mediafront Version7.x-2.0 Updatebeta5
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc1
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc2
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc3
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc4
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc5
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc6
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc7
Mediafront ≫ Mediafront Version7.x-2.0 Updaterc8
Mediafront ≫ Mediafront Version7.x-2.x Updatedev
Mediafront ≫ Mediafront Version7.x-1.0 Update-
Mediafront ≫ Mediafront Version7.x-1.0 Updatebeta1
Mediafront ≫ Mediafront Version7.x-1.0 Updatebeta2
Mediafront ≫ Mediafront Version7.x-1.0 Updatebeta3
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc1
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc2
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc3
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc4
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc5
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc6
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc7
Mediafront ≫ Mediafront Version7.x-1.0 Updaterc8
Mediafront ≫ Mediafront Version7.x-1.1
Mediafront ≫ Mediafront Version7.x-1.2
Mediafront ≫ Mediafront Version7.x-1.3
Mediafront ≫ Mediafront Version7.x-1.4
Mediafront ≫ Mediafront Version7.x-1.5
Mediafront ≫ Mediafront Version7.x-1.x Updatedev
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.43 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:N/AC:H/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.