4.3
CVSSv2

CVE-2014-8765

Published: 14/10/2014 Updated: 22/10/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the Project Issue File Review module (PIFR) module 6.x-2.x prior to 6.x-2.17 for Drupal allow (1) remote malicious users to inject arbitrary web script or HTML via a crafted patch, which triggers a PIFR client to test the patch and return the results to the PIFR_Server test results page or (2) remote authenticated users with the "manage PIFR environments" permission to inject arbitrary web script or HTML via vectors involving a PIFR_Server administrative page.

Vulnerable Product Search on Vulmon Subscribe to Product

drupal project issue file review 6.x-2.15

drupal project issue file review 6.x-2.14

drupal project issue file review 6.x-2.12

drupal project issue file review 6.x-2.08

drupal project issue file review 6.x-2.07

drupal project issue file review 6.x-2.00

drupal project issue file review 6.x-2.05

drupal project issue file review 6.x-2.04

drupal project issue file review 6.x-2.03

drupal project issue file review 6.x-2.02

drupal project issue file review

drupal project issue file review 6.x-2.10

drupal project issue file review 6.x-2.13

drupal project issue file review 6.x-2.06

drupal project issue file review 6.x-2.01