{"api_version":"1","generated_at":"2026-07-23T05:39:34+00:00","cve":"CVE-2014-9346","urls":{"html":"https://cve.report/CVE-2014-9346","api":"https://cve.report/api/cve/CVE-2014-9346.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-9346","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-9346"},"summary":{"title":"CVE-2014-9346","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for instances with Save term lineage enabled or (2) entity type fields.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-12-08 16:59:18","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/60511","name":"http://secunia.com/advisories/60511","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA60511 - Drupal Hierarchical Select Module Two Script Insertion Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.drupal.org/node/2385933","name":"https://www.drupal.org/node/2385933","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"hierarchical_select 6.x-3.9 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99136","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.drupal.org/node/2386615","name":"https://www.drupal.org/node/2386615","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SA-CONTRIB-2014-117 - Hierarchical Select - Cross Site Scripting (XSS) | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-9346","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9346","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"9346","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hierarchical_select_project","cpe5":"hierarchical_select","cpe6":"6.x-3.x","cpe7":"dev","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:40:25.107Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"hierarchicalselect-hierarchicalselect-xss(99136)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99136"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.drupal.org/node/2385933"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.drupal.org/node/2386615"},{"name":"60511","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/60511"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-12-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for instances with Save term lineage enabled or (2) entity type fields."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-07T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"hierarchicalselect-hierarchicalselect-xss(99136)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99136"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.drupal.org/node/2385933"},{"tags":["x_refsource_MISC"],"url":"https://www.drupal.org/node/2386615"},{"name":"60511","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/60511"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-9346","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for instances with Save term lineage enabled or (2) entity type fields."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"hierarchicalselect-hierarchicalselect-xss(99136)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/99136"},{"name":"https://www.drupal.org/node/2385933","refsource":"CONFIRM","url":"https://www.drupal.org/node/2385933"},{"name":"https://www.drupal.org/node/2386615","refsource":"MISC","url":"https://www.drupal.org/node/2386615"},{"name":"60511","refsource":"SECUNIA","url":"http://secunia.com/advisories/60511"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-9346","datePublished":"2014-12-08T16:00:00.000Z","dateReserved":"2014-12-08T00:00:00.000Z","dateUpdated":"2024-08-06T13:40:25.107Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-12-08 16:59:18","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.0:*:*:*:*:drupal:*:*","matchCriteriaId":"1B57470E-2D03-4504-A6C4-6CCAFEAE625E"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.1:*:*:*:*:drupal:*:*","matchCriteriaId":"51514D79-C6AA-4B79-B351-BB03856B1504"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.2:*:*:*:*:drupal:*:*","matchCriteriaId":"7CF15DE5-08AA-478D-930D-1CCC552CADD1"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.3:*:*:*:*:drupal:*:*","matchCriteriaId":"BCC1AD81-EDEE-4735-91D6-85BBC41976D6"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.4:*:*:*:*:drupal:*:*","matchCriteriaId":"521F312F-81A6-4D60-84BD-FE028FEA6A83"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.5:*:*:*:*:drupal:*:*","matchCriteriaId":"D49757D6-D6C6-48E9-BB5D-53E5E949BFA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.6:*:*:*:*:drupal:*:*","matchCriteriaId":"F2A409BD-BBF8-4A20-9778-EF6EED489524"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.7:*:*:*:*:drupal:*:*","matchCriteriaId":"DAB5E2BE-A09E-4E92-966D-DB1D68173795"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.8:*:*:*:*:drupal:*:*","matchCriteriaId":"B0DC2E95-260B-4D8D-A5CC-80647047EC26"},{"vulnerable":true,"criteria":"cpe:2.3:a:hierarchical_select_project:hierarchical_select:6.x-3.x:dev:*:*:*:drupal:*:*","matchCriteriaId":"B2780DB1-9572-445D-8466-F0D1CD8C8CEA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"9346","Ordinal":"1","Title":"CVE-2014-9346","CVE":"CVE-2014-9346","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"9346","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the Hierarchical Select module 6.x-3.x before 6.x-3.9 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to the (1) taxonomy term title for instances with Save term lineage enabled or (2) entity type fields.","Type":"Description","Title":"CVE-2014-9346"},{"CveYear":"2014","CveId":"9346","Ordinal":"2","NoteData":"2014-12-08","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"9346","Ordinal":"3","NoteData":"2017-09-07","Type":"Other","Title":"Modified"}]}}}