CVE-2009-4532: XSS
Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform creation privileges, to inject arbitrary web script or HTML via a field label.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4532?
CVE-2009-4532 is rated as a moderate severity vulnerability affecting Drupal's Webform module.
How do I fix CVE-2009-4532?
To fix CVE-2009-4532, upgrade the Webform module to version 5.x-2.8, 6.x-2.8, or later.
Who is affected by CVE-2009-4532?
CVE-2009-4532 affects Drupal installations using the Webform module versions prior to 5.x-2.8 and 6.x-2.8.
What kind of attack can CVE-2009-4532 facilitate?
CVE-2009-4532 can facilitate cross-site scripting (XSS) attacks, permitting the injection of arbitrary scripts.
Is CVE-2009-4532 a remote or local vulnerability?
CVE-2009-4532 is a remote vulnerability that can be exploited by authenticated users with webform creation privileges.