CVE-2009-4513
Drupal Workflow <5.x-2.4 & 6.x-1.2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Workflow module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a module for Drupal, allow remote authenticated users, with "administer workflow" privileges, to inject arbitrary web script or HTML via the name of a (1) workflow or (2) workflow state.
References (7)
Scores
EPSS
0.0026
EPSS Percentile
49.3%
Classification
CWE
CWE-79
Status
published
Affected Products (18)
john_vandyk/workflow
< 5.x-2.3
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
john_vandyk/workflow
... and 3 more
Timeline
Published
Dec 31, 2009
Tracked Since
Feb 18, 2026