CVE-2013-6387

EUVD-2013-6212
Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:S/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
drupaldrupal
7.0
drupaldrupal
7.0:alpha1
drupaldrupal
7.0:alpha2
drupaldrupal
7.0:alpha3
drupaldrupal
7.0:alpha4
drupaldrupal
7.0:alpha5
drupaldrupal
7.0:alpha6
drupaldrupal
7.0:alpha7
drupaldrupal
7.0:beta1
drupaldrupal
7.0:beta2
drupaldrupal
7.0:beta3
drupaldrupal
7.0:dev
drupaldrupal
7.0:rc1
drupaldrupal
7.0:rc2
drupaldrupal
7.0:rc3
drupaldrupal
7.0:rc4
drupaldrupal
7.1
drupaldrupal
7.2
drupaldrupal
7.3
drupaldrupal
7.4
drupaldrupal
7.5
drupaldrupal
7.6
drupaldrupal
7.7
drupaldrupal
7.8
drupaldrupal
7.9
drupaldrupal
7.10
drupaldrupal
7.11
drupaldrupal
7.12
drupaldrupal
7.13
drupaldrupal
7.14
drupaldrupal
7.15
drupaldrupal
7.16
drupaldrupal
7.17
drupaldrupal
7.18
drupaldrupal
7.19
drupaldrupal
7.20
drupaldrupal
7.21
drupaldrupal
7.22
drupaldrupal
7.23
drupaldrupal
7.x-dev:x
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
drupal7
lucid
dne
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected