First published: Mon Feb 16 2009(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Link Module | =5.x-2.5 | |
Drupal Drupal | =5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0603 is classified as a moderate severity vulnerability due to its potential for XSS attacks.
To fix CVE-2009-0603, upgrade the Link module to the latest version or apply supplied patches that mitigate the XSS vulnerability.
Remote authenticated users with 'administer content types' privileges on Drupal 5.10 are affected by CVE-2009-0603.
CVE-2009-0603 facilitates cross-site scripting (XSS) attacks by allowing script injection via the description parameter.
No, the Drupal core is not affected by CVE-2009-0603; the vulnerability is limited to the Link module version 5.x-2.5.