{"api_version":"1","generated_at":"2026-07-23T08:29:15+00:00","cve":"CVE-2015-4387","urls":{"html":"https://cve.report/CVE-2015-4387","api":"https://cve.report/api/cve/CVE-2015-4387.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4387","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4387"},"summary":{"title":"CVE-2015-4387","description":"Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.","state":"PUBLISHED","assigner":"mitre","published_at":"2015-06-15 14:59:43","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.drupal.org/node/2463327","name":"https://www.drupal.org/node/2463327","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"password_policy 7.x-1.11 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2015/04/25/6","name":"http://www.openwall.com/lists/oss-security/2015/04/25/6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE requests for Drupal contributed modules (from SA-CONTRIB-2015-034\n to SA-CONTRIB-2015-099)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.drupal.org/node/2463835","name":"https://www.drupal.org/node/2463835","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Password Policy - Critical - Cross Site Scripting (XSS) - SA-CONTRIB-2015-090 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.drupal.org/node/2463329","name":"https://www.drupal.org/node/2463329","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"password_policy 6.x-1.11 | Drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/74348","name":"http://www.securityfocus.com/bid/74348","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Password policy Module Usernames Multiple Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4387","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4387","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"6.x-1.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4387","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"password_policy_project","cpe5":"password_policy","cpe6":"7.x-1.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:11:12.907Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"74348","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/74348"},{"name":"[oss-security] 20150425 CVE requests for Drupal contributed modules (from SA-CONTRIB-2015-034 to SA-CONTRIB-2015-099)","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2015/04/25/6"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.drupal.org/node/2463329"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://www.drupal.org/node/2463327"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.drupal.org/node/2463835"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-03-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-06-22T21:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"74348","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/74348"},{"name":"[oss-security] 20150425 CVE requests for Drupal contributed modules (from SA-CONTRIB-2015-034 to SA-CONTRIB-2015-099)","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2015/04/25/6"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.drupal.org/node/2463329"},{"tags":["x_refsource_CONFIRM"],"url":"https://www.drupal.org/node/2463327"},{"tags":["x_refsource_MISC"],"url":"https://www.drupal.org/node/2463835"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-4387","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"74348","refsource":"BID","url":"http://www.securityfocus.com/bid/74348"},{"name":"[oss-security] 20150425 CVE requests for Drupal contributed modules (from SA-CONTRIB-2015-034 to SA-CONTRIB-2015-099)","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2015/04/25/6"},{"name":"https://www.drupal.org/node/2463329","refsource":"CONFIRM","url":"https://www.drupal.org/node/2463329"},{"name":"https://www.drupal.org/node/2463327","refsource":"CONFIRM","url":"https://www.drupal.org/node/2463327"},{"name":"https://www.drupal.org/node/2463835","refsource":"MISC","url":"https://www.drupal.org/node/2463835"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2015-4387","datePublished":"2015-06-15T14:00:00.000Z","dateReserved":"2015-06-05T00:00:00.000Z","dateUpdated":"2024-08-06T06:11:12.907Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-06-15 14:59:43","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.0:*:*:*:*:drupal:*:*","matchCriteriaId":"0E36275F-DDF4-4C53-A7C4-4B241FB440CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.1:*:*:*:*:drupal:*:*","matchCriteriaId":"12E5640E-3387-45FD-88D7-EB169950FFBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.2:*:*:*:*:drupal:*:*","matchCriteriaId":"92C727B1-5A9E-4729-B4FD-55D444B4DF56"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.3:*:*:*:*:drupal:*:*","matchCriteriaId":"5952CF6A-FB88-4905-AD5F-892F4AAB68A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.4:*:*:*:*:drupal:*:*","matchCriteriaId":"AFE38ABE-F420-40B1-BED6-7DFCB71919BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.5:*:*:*:*:drupal:*:*","matchCriteriaId":"0B533DD1-B748-41F5-A8DB-62442D71082F"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.6:*:*:*:*:drupal:*:*","matchCriteriaId":"C16F12FA-A574-483C-8DE9-A1FB895C058C"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.7:*:*:*:*:drupal:*:*","matchCriteriaId":"B62C3DA8-521C-4D05-A8F8-B3093FA793A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.8:*:*:*:*:drupal:*:*","matchCriteriaId":"C55CA63E-03DA-45B6-B1DE-A73D142513F9"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.9:*:*:*:*:drupal:*:*","matchCriteriaId":"1202BC2B-EC43-45B4-8A35-D885729B9A4F"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:6.x-1.10:*:*:*:*:drupal:*:*","matchCriteriaId":"2504C085-4E06-4614-86B8-A22E3DB14A9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.0:*:*:*:*:drupal:*:*","matchCriteriaId":"F6945F71-85FB-4F61-9054-9BED26F37433"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.1:*:*:*:*:drupal:*:*","matchCriteriaId":"C94C4CAB-3C66-46FE-9BE8-0D34C5169941"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.2:*:*:*:*:drupal:*:*","matchCriteriaId":"E1C6CF77-6047-4FAB-ADD2-CCB1677B8726"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.3:*:*:*:*:drupal:*:*","matchCriteriaId":"EC20F503-07C6-48B7-912C-C766E753B32B"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.4:*:*:*:*:drupal:*:*","matchCriteriaId":"6CA9D468-8239-42C4-BC5D-835F48B4927C"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.5:*:*:*:*:drupal:*:*","matchCriteriaId":"6FF59E97-C0E3-4110-9B40-B8EE0AAE5DC7"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.6:*:*:*:*:drupal:*:*","matchCriteriaId":"B8E83416-2CB7-4242-956F-0C1DCC716472"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.7:*:*:*:*:drupal:*:*","matchCriteriaId":"5873D455-B476-486F-A6CD-42D5B991E380"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.8:*:*:*:*:drupal:*:*","matchCriteriaId":"C5823CF1-990F-4536-9C80-9B5C3E342897"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.9:*:*:*:*:drupal:*:*","matchCriteriaId":"5D2E948B-CFF2-453D-B8F3-13D8CCDC9A2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:password_policy_project:password_policy:7.x-1.10:*:*:*:*:drupal:*:*","matchCriteriaId":"BE332B3D-D3D3-4BD7-87B7-3EC01B41B304"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4387","Ordinal":"1","Title":"CVE-2015-4387","CVE":"CVE-2015-4387","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4387","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Password Policy module 6.x-1.x before 6.x-1.11 and 7.x-1.x before 7.x-1.11 for Drupal, when a site has a policy that uses the username constraint, allows remote attackers to inject arbitrary web script or HTML via a crafted username that is imported from an external source.","Type":"Description","Title":"CVE-2015-4387"},{"CveYear":"2015","CveId":"4387","Ordinal":"2","NoteData":"2015-06-15","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4387","Ordinal":"3","NoteData":"2015-06-22","Type":"Other","Title":"Modified"}]}}}