PT-2009-3650 · Drupal · Drupal Content Construction Kit
Published
2009-03-24
·
Updated
2017-08-17
·
CVE-2009-1069
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Content Construction Kit (CCK) versions 6.x before 6.x-2.2
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature of the Drupal Content Construction Kit (CCK) module. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the vulnerabilities are found in the titles of candidate referenced nodes in the Node reference sub-module and the names of candidate referenced users in the User reference sub-module.
Recommendations
For versions prior to 6.x-2.2, update to version 6.x-2.2 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal Content Construction Kit