Drupal是Drupal社区的一套使用PHP语言开发的开源内容管理系统。 Search Autocomplete 7.x-4.8版本 for Drupal 7.x版本中存在跨站脚本漏洞,该漏洞源于程序对用户提交的输入验证不当。远程攻击者可借助特制的URL利用该漏洞在用户的Web浏览器中执行脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Drupal | 3rd party module - Search Autocomplete | 7.x-4.x ~ 7.x-4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-6921 | File REST resource does not properly validate | |
| CVE-2017-6924 | REST API can bypass comment approval - Access Bypass - Moderately Critical |
No comments yet