« Volver al listado

CVE-2018-7603

Estado: ModificadaMedia (6.1)—

In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). The module doesn't sufficiently filter user-entered text among the autocompletion items leading to a Cross Site Scripting (XSS) vulnerability. This vulnerability can be exploited by any user allowed to create one of the autocompletion item, for instance, nodes, users, comments.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-7603",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "mlhess@drupal.org",
      "affectedData": [
        {
          "vendor": "Drupal",
          "product": "3rd party module - Search Autocomplete",
          "versions": [
            {
              "status": "affected",
              "version": "7.x-4.x",
              "lessThan": "7.x-4.8",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-01-15T22:29:00.297",
  "references": [
    {
      "url": "https://www.drupal.org/sa-contrib-2018-070",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "mlhess@drupal.org"
    },
    {
      "url": "https://www.drupal.org/sa-contrib-2018-070",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Drupal's 3rd party module search auto complete prior to versions 7.x-4.8 there is a Cross Site Scripting vulnerability. This Search Autocomplete module enables you to autocomplete textfield using data from your website (nodes, comments, etc.). The module doesn't sufficiently filter user-entered text among the autocompletion items leading to a Cross Site Scripting (XSS) vulnerability. This vulnerability can be exploited by any user allowed to create one of the autocompletion item, for instance, nodes, users, comments."
    },
    {
      "lang": "es",
      "value": "En el módulo de terceros Search Autocomplete de Drupal, en versiones anteriores a la 7.x-4.8, hay una vulnerabilidad Cross-Site Scripting (XSS). Este módulo permite autocompletar campos de texto utilizando datos de un sitio web (nodos, comentarios, etc.). El módulo no filtra totalmente el texto introducido por el usuario de los ítems de autocompletado, lo que conduce a una vulnerabilidad Cross-Site Scripting (XSS). Esta vulnerabilidad puede ser explotada por cualquier usuario a l que se le permita crear uno de los ítems de autocompletado, como nodos, usuarios o comentarios."
    }
  ],
  "lastModified": "2026-06-17T02:03:26.440",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:search_autocomplete_project:search_autocomplete:*:*:*:*:*:drupal:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B2CE4D8-C39B-465A-B0C7-598021B575B6",
              "versionEndExcluding": "7.x-4.8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "mlhess@drupal.org"
}