CVE-2009-1823: XSS
Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.7 and 6.x before 6.x-1.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML by modifying a document head, before the Content-Type META element, to contain crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6 and 7, a related issue to CVE-2009-1575.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1823?
CVE-2009-1823 has been classified as a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2009-1823?
To fix CVE-2009-1823, update the Drupal Print module to versions 5.x-4.7 or 6.x-1.7 and higher.
What software is affected by CVE-2009-1823?
CVE-2009-1823 affects the Drupal Print module versions 5.x before 4.7 and 6.x before 1.7.
What type of vulnerability is CVE-2009-1823?
CVE-2009-1823 is a cross-site scripting (XSS) vulnerability allowing remote attackers to inject arbitrary web scripts or HTML.
What can attackers exploit in CVE-2009-1823?
Attackers can exploit CVE-2009-1823 by modifying document headers to execute malicious scripts in the context of a user's session.