CVE-2009-1035: XSS
Cross-site scripting (XSS) vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via Cascading Style Sheets (CSS).
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker must be authenticated to the Drupal site. The issue can be exploited remotely by an authenticated user.
Which releases should be considered affected?
Tasklist 5.x-1.x releases before 5.x-1.3 and Tasklist 5.x-2.x releases before 5.x-2.0-alpha1 are affected. Systems running those release ranges should be upgraded to the specified fixed release or later.
What can successful exploitation allow?
An authenticated attacker can inject arbitrary web script or HTML through Cascading Style Sheets input. This can compromise the integrity of content viewed by users of the affected site.