CVE-2010-1584

Drupal <6.x-2.0-rc4 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.

Scores

EPSS 0.0033
EPSS Percentile 55.2%

Classification

CWE
CWE-79
Status published

Affected Products (13)

steven_jones/context < 6.x-2.0
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
steven_jones/context
n/a/n/a

Timeline

Published May 19, 2010
Tracked Since Feb 18, 2026