CVE-2018-25085
Responsive Menus Configuration Setting responsive_menus.module responsive_menus_admin_form_submit cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 7.x-1.7 is able to address this issue. The patch is named 3c554b31d32a367188f44d44857b061eac949fb8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227755.
In Responsive Menus 7.x-1.x-dev für Drupal wurde eine problematische Schwachstelle entdeckt. Es geht um die Funktion responsive_menus_admin_form_submit der Datei responsive_menus.module der Komponente Configuration Setting Handler. Dank der Manipulation mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Ein Aktualisieren auf die Version 7.x-1.7 vermag dieses Problem zu lösen. Der Patch wird als 3c554b31d32a367188f44d44857b061eac949fb8 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-04-29 CVE Reserved
- 2023-05-01 CVE Published
- 2024-08-05 CVE Updated
- 2024-11-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.227755 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.drupal.org/sa-contrib-2018-079 | 2024-05-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Responsive Menus Search vendor "Drupal" for product "Responsive Menus" | < 7.x-1.7 Search vendor "Drupal" for product "Responsive Menus" and version " < 7.x-1.7" | drupal |
Affected
|