CVE-2010-2472: XSS
Published Nov 7, 2019
·Updated
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which could allow an attacker to perform a cross-site scripting (XSS) attack. This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer languages' permission.
Affected Software
3 affected components
debian/drupal6
Drupal Drupal>=6.0<6.16
Drupal Drupal>=5.0<5.22
Remediation
Patch Available
Event History
Nov 7, 2019
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2010-2472?
The severity of CVE-2010-2472 is medium.
2
How does CVE-2010-2472 affect Drupal?
CVE-2010-2472 affects Drupal versions 6.x before 6.16 and 5.x before 5.22.
3
What is the vulnerability in CVE-2010-2472?
The vulnerability in CVE-2010-2472 is a cross-site scripting (XSS) attack.
4
What is the mitigation for CVE-2010-2472?
There are no known remedies for CVE-2010-2472.
5
Where can I find more information about CVE-2010-2472?
You can find more information about CVE-2010-2472 at the following references: [link1] [link2] [link3]