VulnerabilityModified
CVE-2013-1971
Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file.
LOW 2.1EPSS 0.93%
Does this matter?
Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file.
- CVSS 2.0
- 2.1 LOWAV:N/AC:H/Au:S/C:N/I:P/A:N
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jordan de laune/mp3 player
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/59276Vendor Advisory
- https://drupal.org/node/1972804Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83649
- http://www.securityfocus.com/bid/59276Vendor Advisory
- https://drupal.org/node/1972804Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83649
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.