Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-12-21T16:00:00
Updated: 2024-08-07T07:01:20.082Z
Reserved: 2009-12-21T00:00:00
Link: CVE-2009-4371
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-12-21T16:30:00.687
Modified: 2024-11-21T01:09:29.363
Link: CVE-2009-4371
Redhat
No data.