PT-2010-2154 · Drupal · Drupal Node Blocks Module
Published
2010-01-21
·
Updated
2018-10-10
·
CVE-2010-0370
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Node Blocks module versions 5.x-1.1 and earlier
Drupal Node Blocks module versions 6.x-1.3 and earlier
Description
A cross-site scripting issue allows remote authenticated users with permissions to create or edit content and administer blocks to inject arbitrary web script or HTML via the
edit-title parameter, also known as the block title.Recommendations
For Drupal Node Blocks module versions 5.x-1.1 and earlier, update to a version later than 5.x-1.1 to resolve the issue.
For Drupal Node Blocks module versions 6.x-1.3 and earlier, update to a version later than 6.x-1.3 to resolve the issue.
As a temporary workaround, consider restricting access to the block title editing feature to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal Node Blocks Module