CVE-2010-0370: XSS
Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and administer blocks, to inject arbitrary web script or HTML via the edit-title parameter (aka block title).
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0370?
CVE-2010-0370 is classified as a medium severity vulnerability due to its ability to allow cross-site scripting (XSS) attacks on affected Drupal modules.
How do I fix CVE-2010-0370?
To fix CVE-2010-0370, upgrade the Node Blocks module to version 5.x-1.2 or 6.x-1.4 or later.
Who is affected by CVE-2010-0370?
Users of the Node Blocks module for Drupal versions 5.x-1.1 and earlier, and 6.x-1.3 and earlier are affected by CVE-2010-0370.
What type of vulnerability is CVE-2010-0370?
CVE-2010-0370 is a cross-site scripting (XSS) vulnerability.
Can I prevent CVE-2010-0370 from being exploited?
Preventing CVE-2010-0370 from being exploited involves ensuring that only trusted users have permissions to create or edit content and administer blocks.