CVE-2010-1358: XSS
Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1358?
CVE-2010-1358 is considered a moderate severity vulnerability due to its ability to allow XSS attacks for users with specific privileges.
How do I fix CVE-2010-1358?
To fix CVE-2010-1358, update the Bibliography module to version 5.x-1.18 or 6.x-1.10 or later.
Who is affected by CVE-2010-1358?
CVE-2010-1358 affects remote authenticated users with 'administer biblio' privileges on Drupal sites.
What types of attacks can be executed due to CVE-2010-1358?
CVE-2010-1358 allows remote authenticated users to inject arbitrary web scripts or HTML, potentially leading to XSS attacks.
What versions of the Bibliography module are vulnerable to CVE-2010-1358?
CVE-2010-1358 affects Bibliography module versions 5.x through 5.x-1.17 and 6.x through 6.x-1.9.