PT-2009-5010 · Drupal · Links Package+1
Published
2009-07-27
·
Updated
2009-07-27
·
CVE-2009-2610
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Links Package versions 5.x before 5.x-1.13
Links Package versions 6.x before 6.x-1.2
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the Links Related module. This allows remote authenticated users to inject arbitrary web script or HTML via the
title field.Recommendations
For Links Package versions 5.x before 5.x-1.13, update to version 5.x-1.13 or later.
For Links Package versions 6.x before 6.x-1.2, update to version 6.x-1.2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Links Package
Links Related Module