60734Third-party advisory
http://secunia.com/advisories/60734 CVE-2014-8379
marketo_ma_project marketo_ma Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2014-8379 has a selected CVSS score of 3.5.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to field titles to the (1) Webform or (2) User sub-modules.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
marketo_maBrowse marketo_ma_project / marketo_ma | VulnCheck | Version data not supplied | |
References
569340vdb entry
http://www.securityfocus.com/bid/69340 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8379 drupal.orgConfirmation
https://www.drupal.org/node/2324777 drupal.org
https://www.drupal.org/node/2324813