CVE-2022-50957 | avatar_uploader 7.0-1.0-beta8 on Drupal avatar_uploader.pages.inc File cross site scripting (Exploit 50841 / EDB-50841)
A vulnerability was found in avatar_uploader 7.0-1.0-beta8 on Drupal and classified as problematic. This issue affects some unknown processing of the file avatar_uploader.pages.inc. The manipulation of the argument File results in cross site scripting.
This vulnerability is known as CVE-2022-50957. It is possible to launch the attack remotely. Furthermore, an exploit is available.