First published: Tue Jan 12 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Randomizer | =5.x-1.0 | |
Drupal Randomizer | =6.x-1.0 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4602 is considered a moderate risk due to potential cross-site scripting (XSS) attacks.
To fix CVE-2009-4602, update the Randomizer module to a version beyond 5.x-1.0 or 6.x-1.0.
CVE-2009-4602 affects users of the Randomizer module in Drupal versions 5.x-1.0 and 6.x-1.0.
CVE-2009-4602 is a cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary scripts.
The potential impacts of CVE-2009-4602 include unauthorized script execution in users' browsers, leading to session hijacking or data theft.