5.4
CVE-2016-1913
- EPSS 0.62%
- Veröffentlicht 15.01.2016 20:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
Multiple cross-site scripting (XSS) vulnerabilities in the Redhen module 7.x-1.x before 7.x-1.11 for Drupal allow remote authenticated users with certain access to inject arbitrary web script or HTML via unspecified vectors, related to (1) individual contacts, (2) notes, or (3) engagement scores.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhen Project ≫ Redhen Version 7.x-1.0 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.0 Update alpha1 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.0 Update alpha2 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.0 Update alpha3 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.0 Update beta1 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.0 Update beta2 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.0 Update beta3 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.1 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.2 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.3 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.4 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.5 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.6 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.7 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.8 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.10 SwPlatform drupal
Redhen Project ≫ Redhen Version 7.x-1.x Update dev SwPlatform drupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.62% | 0.447 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.3 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://www.drupal.org/node/2649780
https://www.drupal.org/node/2649800