SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-2372

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML,…

MEDIUM 6.5EPSS 2.31%

Does this matter?

Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.

Description

Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
2.31% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
drupal/drupal
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.