« Volver al listado

CVE-2015-4387

Estado: ModificadaBaja (2.6)—

Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-4387",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-06-15T14:59:43.013",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/04/25/6",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/74348",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2463327",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2463329",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.drupal.org/node/2463835",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/04/25/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/74348",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2463327",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2463329",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.drupal.org/node/2463835",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de XSS en páginas de administración no especificadas en el módulo Password Policy 6.x-1.x anterior a 6.x-1.11 y 7.x-1.x anterior a 7.x-1.11 , cuando un sitio tiene una política que utiliza la limitación del nombre de usuario, permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de un nombre de usuario manipulado que se importa de una fuente externa."
    }
  ],
  "lastModified": "2026-06-17T00:27:12.667",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E36275F-DDF4-4C53-A7C4-4B241FB440CE"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12E5640E-3387-45FD-88D7-EB169950FFBC"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92C727B1-5A9E-4729-B4FD-55D444B4DF56"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.3:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5952CF6A-FB88-4905-AD5F-892F4AAB68A6"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.4:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFE38ABE-F420-40B1-BED6-7DFCB71919BB"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.5:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B533DD1-B748-41F5-A8DB-62442D71082F"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.6:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C16F12FA-A574-483C-8DE9-A1FB895C058C"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.7:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B62C3DA8-521C-4D05-A8F8-B3093FA793A4"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.8:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C55CA63E-03DA-45B6-B1DE-A73D142513F9"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.9:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1202BC2B-EC43-45B4-8A35-D885729B9A4F"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:6.x-1.10:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2504C085-4E06-4614-86B8-A22E3DB14A9D"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.0:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6945F71-85FB-4F61-9054-9BED26F37433"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.1:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C94C4CAB-3C66-46FE-9BE8-0D34C5169941"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.2:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1C6CF77-6047-4FAB-ADD2-CCB1677B8726"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.3:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC20F503-07C6-48B7-912C-C766E753B32B"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.4:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CA9D468-8239-42C4-BC5D-835F48B4927C"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.5:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FF59E97-C0E3-4110-9B40-B8EE0AAE5DC7"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.6:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8E83416-2CB7-4242-956F-0C1DCC716472"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.7:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5873D455-B476-486F-A6CD-42D5B991E380"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.8:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5823CF1-990F-4536-9C80-9B5C3E342897"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.9:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D2E948B-CFF2-453D-B8F3-13D8CCDC9A2D"
            },
            {
              "criteria": "cpe:2.3:a:password_policy_project:password_policy:7.x-1.10:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE332B3D-D3D3-4BD7-87B7-3EC01B41B304"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}