2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-6807" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2015-09-04T15:59:04.087" ,
2024-11-23 01:05:45 +00:00
"lastModified" : "2024-11-21T02:35:41.190" ,
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cross-site scripting (XSS) vulnerability in the Mass Contact module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the \"administer mass contact\" permission to inject arbitrary web script or HTML via a category label."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de XSS en el m\u00f3dulo Mass Contact 6.x-1.x en versiones anteriores a 6.x-1.6 y 7.x-1.x en versiones anteriores a 7.x-1.1 para Drupal, permite a usuarios remotos autenticados con permiso 'administer mass contact' inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s de una etiqueta de categor\u00eda."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:H/Au:S/C:N/I:P/A:N" ,
2024-11-23 01:05:45 +00:00
"baseScore" : 2.1 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "HIGH" ,
"authentication" : "SINGLE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "PARTIAL" ,
2024-11-23 01:05:45 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "LOW" ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "3EA1FC95-1F03-4DD9-8778-C753E8D4B202"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:alpha1:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "B480497B-9ADB-401D-8ACD-F3D6E8F76CC4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:alpha2:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "AFEF6C58-AD7E-476F-918B-95A29D0838C9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:alpha3:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "5A933FEA-0CAA-456E-B1FF-4E6335DCC3C5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:alpha4:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "EA0DF198-2551-48B8-B6B5-94BF85F06EA2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:alpha5:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "351AA8DD-79A7-4F6D-98F8-25A42A137212"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:alpha6:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "BBD89401-E4E9-4913-86CE-609AAE2A6F55"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:beta1:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "9A2A4BF6-5AEB-463C-A79F-59E853FF49FF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:beta2:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "F322D3CF-7535-4867-8545-C706414596E0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.0:beta3:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "8EF34E8D-AB0A-483B-8BBC-1C7959FF27E7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:7.x-1.x:dev:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "01202E8E-EF37-4AF2-8739-64E5AD91FC73"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.0:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "98104EAC-2102-4400-9DBC-82CE6416F9FA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.0:beta1:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "7D1D3566-AEC4-4DC1-9E22-A9E02EFC9860"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.0:beta2:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "B6DE32ED-D729-49F5-B2E9-E2A75A2B626D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.1:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "6BA61673-B389-4E4F-ACAB-EFBC05867BA4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.2:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "D87502B7-9F4F-4BC5-9962-9B2F16BEF81D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.3:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "392CD27A-716B-4D28-99DA-FBEB066CF240"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.4:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "33889DE3-DA8E-4D92-9BDC-9EEFCD7DEDC9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.5:*:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "3D13E645-CFEE-4A2B-A5D2-F7D72AF3B55F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:mass_contact_project:mass_contact:6.x-1.x:dev:*:*:*:drupal:*:*" ,
"matchCriteriaId" : "1FB7DEC1-CAE8-4219-8E5F-08D4EA11099E"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.drupal.org/node/2561695" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "https://www.drupal.org/node/2561699" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "https://www.drupal.org/node/2561951" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2024-11-23 01:05:45 +00:00
} ,
{
"url" : "https://www.drupal.org/node/2561695" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "https://www.drupal.org/node/2561699" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch"
]
} ,
{
"url" : "https://www.drupal.org/node/2561951" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}