Vulnerability Description
A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Drupal | Data | 6.x-1.0 |
| Drupal | Drupal | 6.20 |
Related Weaknesses (CWE)
References
- https://seclists.org/fulldisclosure/2011/Feb/219Mailing ListThird Party Advisory
- https://www.drupal.org/node/1056470Vendor Advisory
- https://www.openwall.com/lists/oss-security/2011/07/26/8Mailing ListThird Party Advisory
- https://seclists.org/fulldisclosure/2011/Feb/219Mailing ListThird Party Advisory
- https://www.drupal.org/node/1056470Vendor Advisory
- https://www.openwall.com/lists/oss-security/2011/07/26/8Mailing ListThird Party Advisory
FAQ
What is CVE-2011-2714?
CVE-2011-2714 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.
How severe is CVE-2011-2714?
CVE-2011-2714 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2714?
Check the references section above for vendor advisories and patch information. Affected products include: Drupal Data, Drupal Drupal.