CVE-2009-1047
Drupal - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vectors involving outbound HTML e-mail.
Scores
EPSS
0.0020
EPSS Percentile
42.4%
Classification
CWE
CWE-79
Status
published
Affected Products (34)
drupal/drupal
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
drupal/print
... and 19 more
Timeline
Published
Mar 23, 2009
Tracked Since
Feb 18, 2026