CVE-2011-4560: XSS
Published Nov 28, 2011
·Updated
Cross-site scripting (XSS) vulnerability in the Petition Node module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to signing a petition.
Affected Software
12 affected components
Drupal Petition Node module=6.x-1.1
Drupal Petition Node module=6.x-1.1-beta1
Drupal Petition Node module=6.x-1.1-beta2
Drupal Petition Node module=6.x-1.1-beta3
Drupal Petition Node module=6.x-1.1-beta4
Drupal Petition Node module=6.x-1.1-beta5
Drupal Petition Node module=6.x-1.1-beta6
Drupal Petition Node module=6.x-1.1-dev
Drupal Petition Node module=6.x-1.2
Drupal Petition Node module=6.x-1.3
Drupal Petition Node module=6.x-1.4
Drupal Drupal
Event History
Nov 28, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
09:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4560?
CVE-2011-4560 is categorized as a cross-site scripting (XSS) vulnerability with a moderate severity level.
2
How do I fix CVE-2011-4560?
To fix CVE-2011-4560, you should update the Petition Node module to version 6.x-1.5 or later.
3
Who is affected by CVE-2011-4560?
CVE-2011-4560 affects users of the Petition Node module version 6.x-1.x prior to 6.x-1.5 in Drupal.
4
What can attackers do with CVE-2011-4560?
Attackers exploiting CVE-2011-4560 can inject arbitrary web scripts or HTML into the application.
5
Is there a patch available for CVE-2011-4560?
Yes, a patch is available in the form of an updated version of the Petition Node module.