CVE-2009-2372
Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML,…
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- drupal/drupal
- Source
- cve@mitre.org
References
- http://drupal.org/node/507572Patch, Vendor Advisory
- http://osvdb.org/55525Broken Link
- http://secunia.com/advisories/35681Third Party Advisory
- http://www.securitytracker.com/id?1022497Patch, Third Party Advisory, VDB Entry
- http://drupal.org/node/507572Patch, Vendor Advisory
- http://osvdb.org/55525Broken Link
- http://secunia.com/advisories/35681Third Party Advisory
- http://www.securitytracker.com/id?1022497Patch, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.