Cross-Site Scripting Vulnerability in Drupal's Printer, E-mail and PDF Versions Module
CVE-2009-1047

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
23 March 2009

Summary

A cross-site scripting (XSS) vulnerability exists in the Send by e-mail module of the Printer, E-mail and PDF Versions module for Drupal. This flaw allows remote attackers to exploit the application by injecting arbitrary web scripts or HTML content via outbound HTML e-mails. Affected versions include 5.x before 5.x-4.4 and 6.x before 6.x-1.4, highlighting the importance of applying the latest updates to safeguard against potential exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.