CVE-2009-4559

Drupal 6.x <6.x-1.3 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Submitted By module 6.x before 6.x-1.3 for Drupal allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via an input string for "submitted by" text.

Scores

EPSS 0.0016
EPSS Percentile 37.0%

Classification

CWE
CWE-79
Status published

Affected Products (5)

nanwich/submitted_by
nanwich/submitted_by
nanwich/submitted_by
nanwich/submitted_by
n/a/n/a

Timeline

Published Jan 04, 2010
Tracked Since Feb 18, 2026