First published: Fri Jun 05 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Quiz | =6.x-2.0-rc1 | |
Drupal Quiz | =6.x-3.0-beta1 | |
Drupal Quiz | =6.x-2.0-beta1 | |
Drupal Quiz | =5.x | |
Drupal Quiz | =6.x-3.x-rc2 | |
Drupal Quiz | =6.x-2.0-alpha1 | |
Drupal Quiz | =6.x-3.0 | |
Drupal Quiz | =6.x-2.0 | |
Drupal Quiz | =6.x-3.x-dev | |
Drupal Quiz | =6.x-2.0-alpha2 | |
Drupal Quiz | =6.x-2.1 | |
Drupal Quiz | =6.x-2.0-rc2 | |
Drupal Quiz | =6.x-3.0-alpha2 | |
Drupal Quiz | =6.x-2.x-dev | |
Drupal Quiz | =6.x-3.0-alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1942 is classified as a high severity vulnerability due to its potential for exploitation via cross-site scripting.
To mitigate CVE-2009-1942, upgrade the Quiz module to versions 6.x-2.2 or 6.x-3.0 and higher.
CVE-2009-1942 affects the Quiz module versions 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0.
CVE-2009-1942 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially compromising site security.
Remote authenticated users with access to create quizzes or quiz questions are the primary users affected by CVE-2009-1942.