CVE-2009-4513: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Workflow module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a module for Drupal, allow remote authenticated users, with "administer workflow" privileges, to inject arbitrary web script or HTML via the name of a (1) workflow or (2) workflow state.
Affected Software
Event History
Frequently Asked Questions
What are the impacts of CVE-2009-4513?
CVE-2009-4513 allows remote authenticated users with 'administer workflow' privileges to inject arbitrary web scripts or HTML, which can lead to cross-site scripting (XSS) attacks.
What versions of the Workflow module are affected by CVE-2009-4513?
CVE-2009-4513 affects Workflow module versions 5.x before 5.x-2.4 and 6.x before 6.x-1.2.
How do I fix CVE-2009-4513?
To fix CVE-2009-4513, upgrade to Workflow module versions 5.x-2.4 or 6.x-1.2 or later.
What is the severity of CVE-2009-4513?
CVE-2009-4513 has a medium severity rating due to its potential for XSS exploitation.
Who is affected by CVE-2009-4513?
Users with 'administer workflow' privileges in Drupal installations utilizing the affected versions of the Workflow module are vulnerable to CVE-2009-4513.