Description
Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary JavaScript in victim browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Milad karimi
References
www.exploit-db.com/exploits/50841 (ExploitDB-50841)
www.drupal.org/project/avatar_uploader (Product Reference)
www.vulncheck.com/...avatar-uploader-7-x-beta8-reflected-xss (VulnCheck Advisory: Drupal avatar_uploader 7.x-1.0-beta8 Reflected XSS)