PT-2019-6545 · Drupal · Drupal
Jan Lieskovsky
·
Published
2019-11-07
·
Updated
2019-11-13
·
CVE-2010-2472
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions 6.x prior to 6.16
Drupal versions 5.x prior to 5.22
Description
The Locale module and its dependent contributed modules in Drupal do not properly sanitize the display of language codes, native, and English language names. This could allow an attacker to perform a cross-site scripting (XSS) attack. However, the vulnerability is mitigated by the requirement that an attacker must have a role with the
administer languages permission.Recommendations
For versions 6.x prior to 6.16, update to version 6.16 or later.
For versions 5.x prior to 5.22, update to version 5.22 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal