CVE-2009-1047: XSS
Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vectors involving outbound HTML e-mail.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Printer, e-mail and PDF versions - Send by e-mail moduleto a version that resolves this vulnerability.Fixed in 5.x-4.4 - Upgrade
Upgrade
Printer, e-mail and PDF versions - Send by e-mail moduleto a version that resolves this vulnerability.Fixed in 6.x-1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1047?
CVE-2009-1047 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2009-1047?
To fix CVE-2009-1047, update the affected Drupal 'Printer, e-mail and PDF versions' module to version 5.x-4.4 or 6.x-1.4 or later.
What software is affected by CVE-2009-1047?
CVE-2009-1047 affects the 'Printer, e-mail and PDF versions' module versions prior to 5.x-4.4 for Drupal 5.x and 6.x-1.4 for Drupal 6.x.
What type of vulnerability is CVE-2009-1047?
CVE-2009-1047 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Can users mitigate the risks associated with CVE-2009-1047 without updating?
Users cannot fully mitigate the risks of CVE-2009-1047 without updating to a secure version of the affected module.