Unrated severityNVD Advisory· Published Jan 12, 2010· Updated Jun 16, 2026
CVE-2009-4602
CVE-2009-4602
Description
Cross-site scripting (XSS) vulnerability in the Randomizer module 5.x through 5.x-1.0 and 6.x through 6.x-1.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:drupal:randomizer:5.x-1.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:drupal:randomizer:5.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:drupal:randomizer:6.x-1.0:*:*:*:*:*:*:*
- (no CPE)range: <=5.x-1.0, <=6.x-1.0
Patches
Vulnerability mechanics
References
3- drupal.org/node/655668nvdVendor Advisory
- www.vupen.com/english/advisories/2009/3476nvdVendor Advisory
- www.securityfocus.com/bid/37274nvd
News mentions
0No linked articles in our index yet.