CVE-2009-2079: XSS
Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via (1) vocabulary names, (2) synonyms, and (3) term names.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2079?
CVE-2009-2079 is a moderate severity cross-site scripting (XSS) vulnerability affecting the Taxonomy Manager module in Drupal.
How do I fix CVE-2009-2079?
To resolve CVE-2009-2079, upgrade the Taxonomy Manager module to version 5.x-1.2 or 6.x-1.1 or later.
Who is affected by CVE-2009-2079?
CVE-2009-2079 affects remote authenticated users with administer taxonomy privileges or those who can add taxonomy terms.
What versions are vulnerable to CVE-2009-2079?
CVE-2009-2079 impacts Taxonomy Manager versions 5.x-1.0, 5.x-1.1 and 6.x-1.0, including beta versions prior to 6.x-1.1.
What type of vulnerability is CVE-2009-2079?
CVE-2009-2079 is categorized as a cross-site scripting (XSS) vulnerability.