CVE-2022-50957
EUVD-2022-5597810.05.2026, 13:16
Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary JavaScript in victim browsers.
Awaiting analysis
This vulnerability is currently awaiting analysis.