CVE-2010-2048: XSS
Published May 25, 2010
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
40 affected components
Menhir Heartbeat=6.x-2.3
Menhir Heartbeat=6.x-2.3-beta1
Menhir Heartbeat=6.x-2.3-beta2
Menhir Heartbeat=6.x-3.2
Menhir Heartbeat=6.x-3.3
Menhir Heartbeat=6.x-3.x-dev
Menhir Heartbeat=6.x-4.0
Menhir Heartbeat=6.x-4.1
Menhir Heartbeat=6.x-4.2
Menhir Heartbeat=6.x-4.3
Menhir Heartbeat=6.x-4.3-beta1
Menhir Heartbeat=6.x-4.3-beta2
Menhir Heartbeat=6.x-4.3-beta3
Menhir Heartbeat=6.x-4.4
Menhir Heartbeat=6.x-4.5
Menhir Heartbeat=6.x-4.6
Menhir Heartbeat=6.x-4.7
Menhir Heartbeat=6.x-4.8
Menhir Heartbeat=6.x-4.x-dev
Drupal Drupal
All of the following
Any of the following
Menhir Heartbeat=6.x-2.3
Menhir Heartbeat=6.x-2.3-beta1
Menhir Heartbeat=6.x-2.3-beta2
Menhir Heartbeat=6.x-3.2
Menhir Heartbeat=6.x-3.3
Menhir Heartbeat=6.x-3.x-dev
Menhir Heartbeat=6.x-4.0
Menhir Heartbeat=6.x-4.1
Menhir Heartbeat=6.x-4.2
Menhir Heartbeat=6.x-4.3
Menhir Heartbeat=6.x-4.3-beta1
Menhir Heartbeat=6.x-4.3-beta2
Menhir Heartbeat=6.x-4.3-beta3
Menhir Heartbeat=6.x-4.4
Menhir Heartbeat=6.x-4.5
Menhir Heartbeat=6.x-4.6
Menhir Heartbeat=6.x-4.7
Menhir Heartbeat=6.x-4.8
Menhir Heartbeat=6.x-4.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 25, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-2048?
CVE-2010-2048 is classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2010-2048?
To fix CVE-2010-2048, upgrade the Heartbeat module to version 6.x-4.9 or later.
3
What types of attacks are possible with CVE-2010-2048?
CVE-2010-2048 allows remote authenticated users to inject arbitrary web scripts or HTML into the application.
4
Which versions of the Heartbeat module are affected by CVE-2010-2048?
CVE-2010-2048 affects Heartbeat module versions 6.x-2.3 to 6.x-4.8.
5
Who are the potential attackers in the context of CVE-2010-2048?
The potential attackers for CVE-2010-2048 are remote authenticated users with permissions to input content.