← Back

CVE-2017-12630

nvd nist
Published: Dec 18, 2017Modified: May 13, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.

Affected (1)

Products: Apache: Drill
1 product
Drill
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.11.0

Timeline

No history available yet.