VYPR
Unrated severityNVD Advisory· Published Aug 6, 2008· Updated Apr 23, 2026

CVE-2008-3500

CVE-2008-3500

Description

Cross-site scripting (XSS) vulnerability in the Suggested Terms module 5.x before 5.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via crafted Taxonomy terms.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in Drupal Suggested Terms module allows authenticated users to inject arbitrary script via crafted taxonomy terms.

Vulnerability

The Suggested Terms module for Drupal 5.x before version 5.x-1.2 does not properly sanitize taxonomy terms presented in the clickable list, leading to a cross-site scripting vulnerability. Users with the ability to create new taxonomy terms can inject arbitrary script code and HTML. Affected versions are all 5.x releases prior to 5.x-1.2 [1].

Exploitation

An attacker must be an authenticated Drupal user with permission to create taxonomy terms. The attacker crafts a term containing malicious script. When the term is displayed in the suggested terms list on edit pages, the script executes in the context of the victim's browser. The vulnerability is exploited remotely without requiring special network position beyond normal web access [1].

Impact

Successful exploitation allows the attacker to inject arbitrary web script or HTML, potentially leading to administrator access if the victim is an administrator viewing the crafted term. The impact is information disclosure and elevation of privileges [1].

Mitigation

The fixed version is 5.x-1.2, released on June 25, 2008. Users of the Suggested Terms module should upgrade immediately. Drupal core is not affected [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.