CVE-2014-9740

Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in the (1) question and (2) description strings in a confirmation form for a triggering Rules link.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:S/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
rules_link_projectrules_link
7.x-1.0:x
rules_link_projectrules_link
7.x-1.0:x
rules_link_projectrules_link
7.x-1.0:x
rules_link_projectrules_link
7.x-1.0:x
rules_link_projectrules_link
7.x-1.0:x
rules_link_projectrules_link
7.x-1.0:x
𝑥
= Vulnerable software versions