CVE-2014-5022: XSS
Published Jul 22, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.
Affected Software
45 affected components
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.14
Drupal Drupal=7.15
Drupal Drupal=7.16
Drupal Drupal=7.17
Drupal Drupal=7.18
Drupal Drupal=7.19
Drupal Drupal=7.20
Drupal Drupal=7.21
Drupal Drupal=7.22
Drupal Drupal=7.23
Drupal Drupal=7.24
Drupal Drupal=7.25
Drupal Drupal=7.26
Drupal Drupal=7.27
Drupal Drupal=7.28
Drupal Drupal=7.x-dev
Event History
Jul 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5022?
CVE-2014-5022 has a low severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2014-5022?
To fix CVE-2014-5022, you should update your Drupal installation to version 7.29 or later.
3
What versions of Drupal are affected by CVE-2014-5022?
CVE-2014-5022 affects all versions of Drupal 7.x prior to 7.29.
4
What type of vulnerability is CVE-2014-5022?
CVE-2014-5022 is classified as a cross-site scripting (XSS) vulnerability that allows remote attackers to inject web scripts or HTML.
5
Can CVE-2014-5022 be exploited remotely?
Yes, CVE-2014-5022 can be exploited remotely by attackers to execute malicious scripts in the context of users' browsers.