SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0626

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing…

MEDIUM 6.5EPSS 3.38%

Does this matter?

Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.

Description

The comment_form_add_preview function in comment.module in Drupal before 4.7.6, and 5.x before 5.1, and vbDrupal, allows remote attackers with "post comments" privileges and access to multiple input filters to execute arbitrary code by previewing comments, which are not processed by "normal form validation routines."

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
3.38% probability · 88th percentile
CISA KEV
Not listed
Affected
drupal/drupal
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.