CVE-2010-2472
Publication date 7 November 2019
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 4.8 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | High |
User interaction | Required |
Scope | Changed |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |