CVE-2009-4524: XSS
Published Dec 31, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (aka real name) element.
Affected Software
7 affected components
Nancy Wichmann Realname=6.x-1.0
Nancy Wichmann Realname=6.x-1.1
Nancy Wichmann Realname=6.x-1.1-rc1
Nancy Wichmann Realname=6.x-1.1-rc2
Nancy Wichmann Realname=6.x-1.1-rc3
Nancy Wichmann Realname=6.x-1.2
Drupal Drupal
Remediation
Patch Available
Event History
Dec 31, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4524?
CVE-2009-4524 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
2
How do I fix CVE-2009-4524?
To fix CVE-2009-4524, update the RealName module to version 6.x-1.3 or later.
3
What kind of attacks can be executed through CVE-2009-4524?
CVE-2009-4524 can allow remote attackers to inject arbitrary web scripts or HTML into affected systems.
4
Which versions of the RealName module are affected by CVE-2009-4524?
CVE-2009-4524 affects RealName module versions 6.x-1.0 through 6.x-1.2.
5
Is Drupal itself affected by CVE-2009-4524?
No, the Drupal core is not directly affected by CVE-2009-4524; only the RealName module is vulnerable.