CVE-2014-4303
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter…
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter and (2) Facebook username settings.
- CVSS 2.0
- 2.1 LOWAV:N/AC:H/Au:S/C:N/I:P/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- drupac/touch
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/58828Permissions Required, Third Party Advisory
- http://www.securityfocus.com/bid/68045Third Party Advisory, VDB Entry
- https://drupal.org/node/2269483Patch, Third Party Advisory
- https://drupal.org/node/2284415Patch, Third Party Advisory
- http://secunia.com/advisories/58828Permissions Required, Third Party Advisory
- http://www.securityfocus.com/bid/68045Third Party Advisory, VDB Entry
- https://drupal.org/node/2269483Patch, Third Party Advisory
- https://drupal.org/node/2284415Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.