CVE-2007-5621

UnknownEPSS 0.84%

Last modified

CVE-2007-5621 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.

Metrics

EPSS Probability
0.84%

53.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DrupalAsin Field ModuleAll versions
DrupalDrupal4.7
DrupalDrupal5.0
DrupalDrupal5.1
DrupalDrupal5.2
DrupalE-Commerce ModuleAll versions
DrupalFullname Field For CckAll versions
DrupalInvite ModuleAll versions
DrupalNode Relativity ModuleAll versions
DrupalPathauto ModuleAll versions
DrupalPaypal Node ModuleAll versions
DrupalToken Module<= 1.4
DrupalToken Module<= 1.8
DrupalUbercart ModuleAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2007-5621?
Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments privilege to inject arbitrary web script or HTML via unspecified vectors related to (1) comments, (2) vocabulary names, (3) term names, and (4) usernames.
How severe is CVE-2007-5621?
Severity scoring for CVE-2007-5621 is pending analysis. The EPSS model estimates a 0.84% probability of exploitation in the next 30 days.
How do I fix CVE-2007-5621?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2007-5621?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST