PT-2019-6545 · Drupal · Drupal
Jan Lieskovsky
·
Publicado
2019-11-07
·
Atualizado
2019-11-13
·
CVE-2010-2472
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 6.x prior to 6.16
Drupal versions 5.x prior to 5.22
Description
The Locale module and its dependent contributed modules in Drupal do not properly sanitize the display of language codes, native, and English language names. This could allow an attacker to perform a cross-site scripting (XSS) attack. However, the vulnerability is mitigated by the requirement that an attacker must have a role with the
administer languages permission.Recommendations
For versions 6.x prior to 6.16, update to version 6.16 or later.
For versions 5.x prior to 5.22, update to version 5.22 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal