Cross-site Scripting Vulnerability in Drupal Print Module by Drupal
CVE-2009-1823

Currently unrated

Key Information:

Vendor
Drupal
Status
Vendor
CVE Published:
29 May 2009

Summary

The Print module in Drupal is susceptible to a cross-site scripting (XSS) vulnerability. This occurs when an attacker is able to inject arbitrary web scripts or HTML into the application by manipulating the document head to include crafted UTF-8 byte sequences. Internet Explorer versions 6 and 7 interpret these sequences as UTF-7, which can lead to security breaches. This vulnerability affects versions prior to 5.x-4.7 and 6.x-1.7, allowing attackers to exploit the flaw and potentially execute harmful scripts on the user’s system.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.