Cross-Site Scripting Vulnerability in User Karma Module for Drupal
CVE-2008-6275

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
25 February 2009

Summary

The User Karma module for Drupal is affected by a cross-site scripting vulnerability that allows remote attackers to inject arbitrary web scripts or HTML through unspecified messages. This flaw manifests in versions 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, potentially enabling exploitation that could compromise user data and system integrity. Users and administrators are advised to upgrade to the latest versions to mitigate risks associated with this security issue.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.