CVE-2017-12630 describes a stored Cross-Site Scripting (XSS) vulnerability in Apache Drill versions 1.11.0 and earlier. An authenticated attacker can inject arbitrary scripts or HTML via the Query page, which then executes on the Profile page, potentially allowing for cookie theft or other client-side attacks. Rated Medium severity (CVSS 5.4), this vulnerability requires user interaction and low privileges but has a low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.0CPE matchmatch criteria | cpe:2.3:a:apache:drill:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.