CVE-2009-0817
Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or…
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Protected Node module 5.x before 5.x-1.4 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users with "administer site configuration" permissions to inject arbitrary web script or HTML via the Password page info field, which is not properly handled by the protected_node_enterpassword function in protected_node.module.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- drupal/protected node module
- Source
- cve@mitre.org
References
- http://drupal.org/node/385950Exploit, Vendor Advisory
- http://drupal.org/node/386604Patch, Vendor Advisory
- http://drupal.org/node/386606Patch, Vendor Advisory
- http://lampsecurity.org/node/28Exploit, URL Repurposed
- http://osvdb.org/52300
- http://secunia.com/advisories/34060Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0572Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48980
- http://drupal.org/node/385950Exploit, Vendor Advisory
- http://drupal.org/node/386604Patch, Vendor Advisory
- http://drupal.org/node/386606Patch, Vendor Advisory
- http://lampsecurity.org/node/28Exploit, URL Repurposed
- http://osvdb.org/52300
- http://secunia.com/advisories/34060Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0572Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48980
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.