Vulnerability Name: | CCN-86926 | ||||||
Published: | 2013-09-04 | ||||||
Updated: | 2013-09-04 | ||||||
Summary: | Drupal could allow a remote attacker to obtain sensitive information, caused by improper validation of user supplied input by the CSS Selectors. An attacker could exploit this vulnerability using hidden text and links in comments field to view and obtain sensitive information, which could be used to launch further attacks on the system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: BID-62174 Drupal Core CSS Selectors Remote Security Vulnerability Source: CCN Type: SecurityTracker Alert ID: 1028978 Drupal Core CSS Selectors Allow Remote Users to Insert Hidden Text and Links to Obtain Potentially Sensitive Information Source: CCN Type: Drupal Web Site Drupal Source: CCN Type: PSA-2013-001 Drupal core - Users can insert hidden text and links Source: XF Type: UNKNOWN drupal-cssselectors-information-disclosure(86926) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |