First published: Mon Dec 21 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal | =5.10 | |
Drupal | =5.4 | |
Drupal | =6.0-beta2 | |
Drupal | =6.2 | |
Drupal | =5.17 | |
Drupal | =5.13 | |
Drupal | =6.14 | |
Drupal | =6.13 | |
Drupal | =5.12 | |
Drupal | =5.2 | |
Drupal | =6.0-beta4 | |
Drupal | =6.12 | |
Drupal | =5.7 | |
Drupal | =6.0-rc-2 | |
Drupal | =6.4 | |
Drupal | =5.0-rc2 | |
Drupal | =6.11 | |
Drupal | =6.0-beta1 | |
Drupal | =5.16 | |
Drupal | =6.0-rc-1 | |
Drupal | =5.0 | |
Drupal | =6.0-rc-3 | |
Drupal | =5.15 | |
Drupal | =5.x-dev | |
Drupal | =5.18 | |
Drupal | =6.7 | |
Drupal | =5.0-rc1 | |
Drupal | =6.8 | |
Drupal | =6.1 | |
Drupal | =5.6 | |
Drupal | =5.0-beta2 | |
Drupal | =5.1 | |
Drupal | =6.5 | |
Drupal | =5.19 | |
Drupal | =5.5 | |
Drupal | =6.10 | |
Drupal | =6.6 | |
Drupal | =6.0 | |
Drupal | =5.14 | |
Drupal | =5.9 | |
Drupal | =6.0-rc-4 | |
Drupal | =5.8 | |
Drupal | =6.0-beta3 | |
Drupal | =6.3 | |
Drupal | =5.0-beta1 | |
Drupal | =5.11 | |
Drupal | =5.20 | |
Drupal | =6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4369 has a medium severity rating as it allows authenticated users to exploit the XSS vulnerability.
To fix CVE-2009-4369, you should upgrade your Drupal installation to versions 5.21 or 6.15 or later.
CVE-2009-4369 can allow attackers to inject arbitrary web script or HTML, potentially compromising user data or website functionality.
Drupal versions 5.x before 5.21 and 6.x before 6.15 are affected by CVE-2009-4369.
Authenticated users with 'administer site-wide contact form' permissions are vulnerable to CVE-2009-4369.