Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-1.x before 6.x-1.4, a module for Drupal, allows remote authenticated users, with create or edit group nodes permissions, to inject arbitrary web script or HTML via the User-Agent HTTP header, a different issue than CVE-2008-3095.
2009-10-09T14:30:00.530
2025-04-09T00:30:58.490
Deferred
CVSSv2: 3.5 (LOW)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moshe_weitzman | organic_groups | 5.x-7.0 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.0-rc1 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.0-rc2 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.0-rc3 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.0-rc4 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.0-rc5 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.1 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.2 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-7.3 | Yes |
| Application | moshe_weitzman | organic_groups | 5.x-8.0 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-beta1 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc1 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc2 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc3 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc4 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc5 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc6 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc7 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc8 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.0-rc9 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.1 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.2 | Yes |
| Application | moshe_weitzman | organic_groups | 6.x-1.3 | Yes |
| Application | drupal | drupal | * | No |