CVE-2022-50957 Details
Description
Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary JavaScript in victim browsers.
A reflected cross-site scripting vulnerability has been identified in the Drupal Avatar Uploader module, specifically in version 7.x-1.0-beta8. This vulnerability allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter in avatar_uploader.pages.inc. Attackers can craft URLs with script payloads that, when accessed, execute arbitrary JavaScript in the context of the victim's browser.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/project/avatar_uploader | [email protected] | Product |
| https://www.exploit-db.com/exploits/50841 | [email protected] | ExploitVDB Entry |
| https://www.vulncheck.com/advisories/drupal-avatar-uploader-7-x-beta8-reflected-xss | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| avatar uploader project avatar uploader | 7.x-1.0 beta8 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | Initial Analysis | [email protected] |
| May 10, 2026 | New CVE Received | [email protected] |