CVE-2008-5996: XSS
Published Jan 28, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category field.
Affected Software
30 affected components
Link3 Simplenews<=5.x-1.4
Link3 Simplenews<=6.x-1.0
Link3 Simplenews=4.6.x-1.x-dev
Link3 Simplenews=4.7.x-1.0
Link3 Simplenews=4.7.x-1.x-dev
Link3 Simplenews=4.7.x-2.x-dev
Link3 Simplenews=5.x-1.0
Link3 Simplenews=5.x-1.1
Link3 Simplenews=5.x-1.2
Link3 Simplenews=5.x-1.3
Link3 Simplenews=5.x-1.x-dev
Link3 Simplenews=6.x-1.0-beta1
Link3 Simplenews=6.x-1.0-beta2
Link3 Simplenews=6.x-1.x-dev
Drupal Drupal
All of the following
Any of the following
Link3 Simplenews<=5.x-1.4
Link3 Simplenews<=6.x-1.0
Link3 Simplenews=4.6.x-1.x-dev
Link3 Simplenews=4.7.x-1.0
Link3 Simplenews=4.7.x-1.x-dev
Link3 Simplenews=4.7.x-2.x-dev
Link3 Simplenews=5.x-1.0
Link3 Simplenews=5.x-1.1
Link3 Simplenews=5.x-1.2
Link3 Simplenews=5.x-1.3
Link3 Simplenews=5.x-1.x-dev
Link3 Simplenews=6.x-1.0-beta1
Link3 Simplenews=6.x-1.0-beta2
Link3 Simplenews=6.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Jan 28, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
03:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·03:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be authenticated and have the Drupal "administer taxonomy" permission. They can inject script or HTML through a Newsletter category field.
2
Which Simplenews releases are affected?
Affected releases are Simplenews 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4.
3
What should be done to remediate the vulnerability?
Apply the available patch or upgrade to a release at or beyond 5.x-1.5 for the 5.x branch or 6.x-1.0-beta4 for the 6.x branch.