CVE-2014-5021
Published: 22 July 2014
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
Priority
Status
Package | Release | Status |
---|---|---|
drupal7 Launchpad, Ubuntu, Debian |
trusty |
Needed
|
vivid |
Not vulnerable
(7.32-1)
|
|
artful |
Not vulnerable
(7.32-1)
|
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lucid |
Does not exist
|
|
lunar |
Does not exist
|
|
precise |
Ignored
(end of life)
|
|
upstream |
Released
(7.29)
|
|
utopic |
Not vulnerable
(7.32-1)
|
|
wily |
Not vulnerable
(7.32-1)
|
|
xenial |
Not vulnerable
(7.32-1)
|
|
yakkety |
Not vulnerable
(7.32-1)
|
|
zesty |
Not vulnerable
(7.32-1)
|
|
mantic |
Does not exist
|
|
drupal6 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lucid |
Ignored
(end of life)
|
|
lunar |
Does not exist
|
|
precise |
Ignored
(end of life)
|
|
trusty |
Does not exist
|
|
upstream |
Released
(6.32)
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
mantic |
Does not exist
|