[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-6929 -- drupal7

ID: oval:org.secpod.oval:def:1900456Date: (C)2019-02-28   (M)2023-12-20
Class: VULNERABILITYFamily: unix




A jQuery cross site scripting vulnerability is present when making Ajaxrequests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in order to exploit. For Drupal 8, this vulnerability was already fixed in Drupal 8.4.0 in the Drupal core upgrade to jQuery 3. For Drupal 7, it is fixed in the current release for jQuery 1.4.4 as well as for other newer versions of jQuery that might be used on the site, for example using the jQuery Update module.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
drupal7
Reference:
CVE-2017-6929
CVE    1
CVE-2017-6929
CPE    140
cpe:/a:drupal:drupal:7.32
cpe:/a:drupal:drupal:8.0.0:alpha4
cpe:/a:drupal:drupal:7.33
cpe:/a:drupal:drupal:8.0.0:alpha5
...

© SecPod Technologies