Responsive Menus Configuration Setting responsive_menus.module responsive_menus_admin_form_submit cross site scripting

CVE-2018-25085
2.4LOW

Key Information

Vendor
Drupal
Status
Responsive Menus
Vendor
CVE Published:
1 May 2023

Summary

A vulnerability classified as problematic was found in Responsive Menus 7.x-1.x-dev on Drupal. Affected by this vulnerability is the function responsive_menus_admin_form_submit of the file responsive_menus.module of the component Configuration Setting Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 7.x-1.7 is able to address this issue. The patch is named 3c554b31d32a367188f44d44857b061eac949fb8. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-227755.

Affected Version(s)

Responsive Menus = 7.x-1.x-dev

CVSS V3.1

Score:
2.4
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Risk change from: 4.8 to: 2.4 - (LOW)

  • Risk change from: 4.8 to: 2.4 - (LOW)

  • VulDB entry last update

  • Vulnerability published.

  • Vulnerability Reserved.

  • VulDB entry created

  • CVE reserved

  • Advisory disclosed

Collectors

NVD DatabaseMitre Database
.