CVE-2009-0575

Drupal Views Bulk Operations <5.x-1.3 & <6.x-1.4 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the theme_views_bulk_operations_confirmation function in views_bulk_operations.module in Views Bulk Operations 5.x before 5.x-1.3 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to node titles. NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0036
EPSS Percentile 57.6%

Classification

CWE
CWE-79
Status published

Affected Products (11)

drupal/views_bulk_operations < 5.x-1.2
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
drupal/views_bulk_operations
n/a/n/a

Timeline

Published Feb 13, 2009
Tracked Since Feb 18, 2026