CVE-2015-6665
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
4.3
Description
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| fedora | 21 | affected | |
| fedora | 22 | affected | |
| fedora | 23 | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| drupal | drupal | 7.0 | |
| drupal | drupal | 7.1 | |
| drupal | drupal | 7.2 | |
| drupal | drupal | 7.3 | |
| drupal | drupal | 7.4 | |
| drupal | drupal | 7.5 | |
| drupal | drupal | 7.6 | |
| drupal | drupal | 7.7 | |
| drupal | drupal | 7.8 | |
| drupal | drupal | 7.9 | |
| drupal | drupal | 7.10 | |
| drupal | drupal | 7.11 | |
| drupal | drupal | 7.12 | |
| drupal | drupal | 7.13 | |
| drupal | drupal | 7.14 | |
| drupal | drupal | 7.15 | |
| drupal | drupal | 7.16 | |
| drupal | drupal | 7.17 | |
| drupal | drupal | 7.18 | |
| drupal | drupal | 7.19 | |
| drupal | drupal | 7.20 | |
| drupal | drupal | 7.21 | |
| drupal | drupal | 7.22 | |
| drupal | drupal | 7.23 | |
| drupal | drupal | 7.24 | |
| drupal | drupal | 7.25 | |
| drupal | drupal | 7.26 | |
| drupal | drupal | 7.27 | |
| drupal | drupal | 7.28 | |
| drupal | drupal | 7.29 | |
| drupal | drupal | 7.30 | |
| drupal | drupal | 7.33 | |
| drupal | drupal | 7.34 | |
| drupal | drupal | 7.35 | |
| drupal | drupal | 7.36 | |
| drupal | drupal | 7.37 | |
| drupal | drupal | 7.38 | |
| drupal | drupal | 7.x-dev | |
| chaos_tool_suite_project | ctools | 6.x-1.0 | |
| chaos_tool_suite_project | ctools | 6.x-1.1 | |
| chaos_tool_suite_project | ctools | 6.x-1.2 | |
| chaos_tool_suite_project | ctools | 6.x-1.3 | |
| chaos_tool_suite_project | ctools | 6.x-1.4 | |
| chaos_tool_suite_project | ctools | 6.x-1.5 | |
| chaos_tool_suite_project | ctools | 6.x-1.6 | |
| chaos_tool_suite_project | ctools | 6.x-1.7 | |
| chaos_tool_suite_project | ctools | 6.x-1.8 | |
| chaos_tool_suite_project | ctools | 6.x-1.9 | |
| chaos_tool_suite_project | ctools | 6.x-1.11 | |
| chaos_tool_suite_project | ctools | 6.x-1.12 | |
| chaos_tool_suite_project | ctools | 6.x-1.13 | |
| chaos_tool_suite_project | ctools | 6.x-1.x | |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.html
- http://www.debian.org/security/2015/dsa-3346
- http://www.securityfocus.com/bid/76431
- http://www.securitytracker.com/id/1033358
- https://www.drupal.org/SA-CORE-2015-003
- https://www.drupal.org/node/2554133
- https://www.drupal.org/node/2554145
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165061.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165674.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165690.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165695.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165704.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165723.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165724.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165733.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165840.html
- http://www.debian.org/security/2015/dsa-3346
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.