CVE-2010-2123
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in a stormorganization action to index.php; the (7) name parameter in a stormperson action to index.php; the (8) stepno (aka Step no.) or (9) title parameter in a stormtask action to index.php; the (10) title (aka Project) parameter in a stormticket action to index.php; or (11) unspecified parameters in a stormproject action to index.php. NOTE: some of these details are obtained from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N
- Puntuación base: 2.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.51%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0160.html
- http://drupal.org/node/803770
- http://secunia.com/advisories/39732
- http://www.osvdb.org/64616
- http://www.securityfocus.com/bid/40288
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58717
- http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0160.html
- http://drupal.org/node/803770
- http://secunia.com/advisories/39732
- http://www.osvdb.org/64616
- http://www.securityfocus.com/bid/40288
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58717
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-2123",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-06-01T21:30:01.103",
"references": [
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0160.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://drupal.org/node/803770",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/39732",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/64616",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/40288",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/58717",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-05/0160.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://drupal.org/node/803770",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/39732",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/64616",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/40288",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/58717",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in a stormorganization action to index.php; the (7) name parameter in a stormperson action to index.php; the (8) stepno (aka Step no.) or (9) title parameter in a stormtask action to index.php; the (10) title (aka Project) parameter in a stormticket action to index.php; or (11) unspecified parameters in a stormproject action to index.php. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en el módulo Storm v5.x y v6.x anterior a v6.x-1.33para Drupal permite a usuarios autenticados remotamente, con ciertos privilegios del módulo, inyectar código web o HTML a través de los parámetros (1) fullname, (2) address, (3) city, (4) provstate (también conocido como state), (5) phone, o (6) taxid en una acción \"stormorganization\" en index.php; el parámetro (7) name en una acción \"stormperson\" en index.php; los parámetros (8) stepno (también conocido como Step no.) o (9) title en una acción \"stormtask\" en index.php; el parámetro (10) title (también conocido como Project) en una cción \"stormticket\" en index.php; o (11) parámetros sin especificar en una acción \"stormproject\" en index.php. NOTA: algunos de estos detalles se han obtenido de información de terceros"
}
],
"lastModified": "2026-06-16T23:20:01.623",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "718B4A5C-F2A9-42DC-80D4-DE35DE71BDD1"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA7F66DF-755B-457F-9086-28A676F3BCCF"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B76EE866-8CAE-484A-B5EC-7C0D6B9AC8BF"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4FD9336-F070-4D59-8DF2-17D6A70170EF"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31848202-5DCB-41AC-A2EA-8E30FC516D7F"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "99211688-2C2C-4C99-97FB-4D3D04B2116D"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B46AB4CD-A59C-49DE-8FFE-5D2E8BEB6339"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B013C8A8-5DF0-4A60-B68A-2D4BF152247C"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DCB50B2-2BC2-467C-AFE3-7CEBD0B1F49A"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F907A10-5426-4FF6-B6A2-1BFC7C83C876"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "664E489B-0809-4A04-9878-A61C5B6077B8"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CEE28A75-4746-42D4-B68C-85E16FA45F89"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2735DC9-317B-47C4-9A1F-BF63CB42888F"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7C1F2ED-21D4-4B58-893A-938955B017EC"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:5.x-1.x:dev:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A4CC6D5-0B84-4485-8287-544297D6C51D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "43E635EA-61AC-40A4-8288-73E3E5FCE13E"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11A4BD8A-BFFE-44A2-AA57-CC81360899B7"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24D5FF1D-D6EE-4F15-B8E8-B41031D88477"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "733ED38A-A409-4E4E-BE2F-9B7B2C6C4FFB"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54BBE17E-4AF9-4290-AC58-CCB9AE3A06AC"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF3B42E5-EB25-4117-B36F-59DE9C78D549"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E8954D9-44A9-4E71-822D-0A691E93EE3C"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66662533-AC69-4D65-933D-58168C7B75B1"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "716B8287-EF97-4738-9D4A-DB6C95212A9B"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86D011B0-9806-4195-93FE-303ACB24D234"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2080F0BE-E4A8-445B-831C-D18489E95E48"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57166D33-B6B0-47DE-9603-436F083F0393"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4B53D24-33A2-4630-8A7B-3DEB0A91B975"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D8E59A5-5CE4-4922-8368-E6FD0FBF87D1"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8D13A0F-E7A2-447A-AC78-A226C190BDFB"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0914D667-3C7F-48CB-BF14-04109450B69F"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C250B6F-304B-4BA6-B2C5-897A76E33762"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D53C8B02-0D37-4BFF-87FD-618A88785309"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FE1F5F72-265B-42C0-B665-0C219C594701"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D851C9E-FA2D-48B8-AB77-3E49B312348E"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19044A29-2043-4D6E-BA6E-C055994A746D"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.21:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D324D19-629A-4512-9714-2EBE85FFBFA6"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.22:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4286A4F-BFBA-44F4-88E9-3976C0AE7928"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.23:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E68EDCB-AD88-4C88-B058-001BEB684131"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.24:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7AC535E-0ACB-4F0C-871E-8184991F6C53"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.25:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3230D853-6AB9-4C10-929D-89DA826A26B9"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.26:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "640596F7-8AB3-4F81-83B3-E42E297708C3"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.27:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91CF5833-C397-472F-BFB2-D306C057E550"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.28:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35BCDA12-AA33-4BB4-AAA4-ED893669EAC6"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.29:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AD87EF1-7E01-43FE-A1A0-C4A60F2CE77A"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A424B64-2FD8-4C42-B446-81B9C1FE18EC"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.31:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AA7D1D7-644D-4EEC-8783-0AC3A0C1118E"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "469D3270-AE50-4098-89C7-DDF21A5372A5"
},
{
"criteria": "cpe:2.3:a:speedtech:storm:6.x-1.x:dev:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6939DD1F-D81F-4589-A07B-967FBFACB7BC"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "799CA80B-F3FA-4183-A791-2071A7DA1E54"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}