CyberRota Analysis
AI analysis pending.
CVE
CVE-2009-2372
Severity
MEDIUM
CVSS
6.5
EPSS
2.31%
Original NVD Description
Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.