CVE-2009-4371

Drupal Core <6.14-6.15 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Locale module (modules/locale/locale.module) in Drupal Core 6.14, and possibly other versions including 6.15, allows remote authenticated users with "administer languages" permissions to inject arbitrary web script or HTML via the (1) Language name in English or (2) Native language name fields in the Custom language form.

Scores

EPSS 0.0015
EPSS Percentile 35.9%

Classification

CWE
CWE-79
Status published

Affected Products (3)

drupal/drupal
drupal/drupal
n/a/n/a

Timeline

Published Dec 21, 2009
Tracked Since Feb 18, 2026