Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Maestro module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with maestro admin permissions to inject arbitrary web script or HTML via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Drupal ‘Maestro’ 模块跨站请求伪造漏洞和跨站脚本漏洞
Vulnerability Description
Drupal是Drupal社区所维护的一套用PHP语言开发的免费、开源的内容管理系统。 Drupal的Maestro模块中存在一个跨站请求伪造漏洞和一个跨站脚本漏洞。攻击者可利用跨站请求伪造漏洞在用户会话上下文中执行未授权操作,这可能导致其他的攻击;可利用跨站脚本漏洞在受影响站点上下文中执行任意脚本代码,盗取基于cookie的认证证书;也可能造成其他的攻击。Maestro 7.x-1.2之前版本中存在这些漏洞。
CVSS Information
N/A
Vulnerability Type
N/A