Cross-Site Scripting Vulnerability in Apache Drill by Apache
CVE-2017-12630
5.4MEDIUM
What is CVE-2017-12630?
In Apache Drill 1.11.0 and earlier, a Cross-Site Scripting (XSS) vulnerability exists when users submit forms from the Query page. This flaw allows malicious individuals to inject arbitrary HTML or scripts, which can later be executed when the Profile page is accessed. For instance, an attacker could submit a script designed to retrieve cookie information, enabling them to extract sensitive data from the Profile page, thus compromising user accounts and data integrity.
Affected Version(s)
Apache Drill 1.11.0 and earlier