CVE-2009-4559
Drupal 6.x <6.x-1.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the Submitted By module 6.x before 6.x-1.3 for Drupal allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via an input string for "submitted by" text.
Scores
EPSS
0.0016
EPSS Percentile
37.0%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
nanwich/submitted_by
nanwich/submitted_by
nanwich/submitted_by
nanwich/submitted_by
n/a/n/a
Timeline
Published
Jan 04, 2010
Tracked Since
Feb 18, 2026