PT-2010-3059 · Drupal · Drupal Own Term Module

Published

2010-04-13

·

Updated

2010-04-14

·

CVE-2010-1362

CVSS v2.0

2.1

Low

VectorAV:N/AC:H/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Drupal Own Term module version 6.x-1.0
Description A cross-site scripting (XSS) issue exists, allowing remote authenticated users with "create additional terms" privileges to inject arbitrary web script or HTML via the term description field in a term listing page.
Recommendations For version 6.x-1.0, consider disabling the term description field in the term listing page until a patch is available. Restrict access to the Own Term module to minimize the risk of exploitation. Avoid using the term description field in the affected module until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1362

Affected Products

Drupal Own Term Module