vendor:
by:
Milad karimi
N/A
CVSS
N/A
Cross Site Scripting (XSS)
CWE
Product Name:
Affected Version From: v7.x-1.0-beta8
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2022
Drupal avatar_uploader v7.x-1.0-beta8 – Cross Site Scripting (XSS)
This plugin creates a avatar_uploader from any post types. The slider import search feature and tab parameter via plugin settings are vulnerable to reflected cross-site scripting.