CVE-2009-4369: XSS
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4369?
CVE-2009-4369 has a medium severity rating as it allows authenticated users to exploit the XSS vulnerability.
How do I fix CVE-2009-4369?
To fix CVE-2009-4369, you should upgrade your Drupal installation to versions 5.21 or 6.15 or later.
What impact does CVE-2009-4369 have on my website?
CVE-2009-4369 can allow attackers to inject arbitrary web script or HTML, potentially compromising user data or website functionality.
Is my version of Drupal affected by CVE-2009-4369?
Drupal versions 5.x before 5.21 and 6.x before 6.15 are affected by CVE-2009-4369.
Who is vulnerable to CVE-2009-4369?
Authenticated users with 'administer site-wide contact form' permissions are vulnerable to CVE-2009-4369.