CVE-2014-8743
Published Oct 13, 2014
Last updated 7 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27F5604C-5C95-47CE-A186-B5F7553B26AC" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC851373-F0D6-41F4-B1C3-995AA8561667" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.0:alpha2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "059B0DEE-F4FB-435A-8288-B420DAB84699" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.0:alpha3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0ABC7DF8-9BDB-4265-B3D4-0CA80EBD26C5" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF988F65-3525-4D66-8714-D2854C686D32" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C3D1ED3-3657-4B08-8DCD-6F387942BA9D" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08D4F917-57B1-4DCA-83E4-FA389B79264E" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C6888A9-5E21-4E41-942A-692FB4FF7965" }, { "criteria": "cpe:2.3:a:drupal:maestro:7.x-1.x-dev:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE206D9A-E6CD-41C5-AA8F-5F6AE57B19F8" } ], "operator": "OR" } ] } ]