Cross-site Scripting Vulnerability in Drupal Talk Module by Drupal
CVE-2008-4152

Currently unrated

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
24 September 2008

Summary

A cross-site scripting vulnerability exists in the Talk module for Drupal, affecting versions prior to 5.x-1.3 and 6.x-1.5. This flaw allows authenticated remote users to insert arbitrary web scripts or HTML into the application via node titles, which could lead to a variety of malicious actions such as data theft, session hijacking, or defacement. Proper validation and sanitization measures are essential to mitigate the risk associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.