CVE-2022-50957
EUVD-2022-5597810.05.2026, 13:16
Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary JavaScript in victim browsers.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| avatar_uploader_project | avatar_uploader | 7.x-1.0:x |
𝑥
= Vulnerable software versions