CVE-2009-4370: XSS
Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4370?
CVE-2009-4370 is considered a moderate severity cross-site scripting vulnerability in Drupal Core.
How do I fix CVE-2009-4370?
To fix CVE-2009-4370, update your Drupal installation to version 6.15 or later.
Who is affected by CVE-2009-4370?
CVE-2009-4370 affects authenticated users with permissions to create new menus in Drupal versions prior to 6.15.
What type of vulnerability is CVE-2009-4370?
CVE-2009-4370 is a cross-site scripting (XSS) vulnerability found in the Menu module of Drupal.
What versions of Drupal are impacted by CVE-2009-4370?
Drupal versions 6.x prior to 6.15 are impacted by CVE-2009-4370.