VYPR
Unrated severityNVD Advisory· Published Feb 23, 2011· Updated Apr 29, 2026

CVE-2011-1066

CVE-2011-1066

Description

Cross-site scripting (XSS) vulnerability in the Messaging module 6.x-2.x before 6.x-2.4 and 6.x-4.x before 6.x-4.0-beta8 for Drupal allows remote attackers with administer messaging permissions to inject arbitrary web script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting vulnerability in Drupal Messaging module allows users with administer messaging permissions to inject arbitrary web script or HTML.

Vulnerability

The Messaging module for Drupal 6.x contains a cross-site scripting (XSS) vulnerability in versions 6.x-2.x prior to 6.x-2.4 and 6.x-4.x prior to 6.x-4.0-beta8 [1]. The module fails to sanitize certain user-supplied data before displaying it, allowing injection of arbitrary web script or HTML. The vulnerability is present in the module's handling of unspecified vectors and requires the attacker to have a role with the 'administer messaging' permission [1].

Exploitation

An attacker must possess a Drupal role that has been granted the 'administer messaging' permission, which is typically reserved for trusted users [1]. With this permission, the attacker can craft malicious input that, when processed and displayed by the module, executes arbitrary script in the context of another user's browser session. The exact vectors are not detailed in the available references, but the attack is performed remotely [1].

Impact

Successful exploitation allows the attacker to inject arbitrary web script or HTML, leading to cross-site scripting (XSS) attacks. This can result in session hijacking, defacement, or theft of sensitive data. The advisory notes that this may lead to a malicious user gaining full administrative access [1]. The impact is limited to users who view the affected content, but the attacker's initial privilege requirement mitigates widespread exploitation.

Mitigation

The vulnerability is fixed in Messaging 6.x-2.4 for the 6.x-2.x branch and Messaging 6.x-4.0-beta8 for the 6.x-4.x branch [1]. Users should upgrade to these versions immediately. No workarounds are provided in the advisory. Drupal core is not affected; only sites using the contributed Messaging module are vulnerable [1]. The fix was released on February 16, 2011, and the CVE was published on February 23, 2011.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

11
  • Reyero/Messaging10 versions
    cpe:2.3:a:reyero:messaging:6.x-2.0:*:*:*:*:*:*:*+ 9 more
    • cpe:2.3:a:reyero:messaging:6.x-2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-4.x:beta1:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-4.x:beta3:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-4.x:beta4:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-4.x:beta5:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-4.x:beta6:*:*:*:*:*:*
    • cpe:2.3:a:reyero:messaging:6.x-4.x:beta7:*:*:*:*:*:*
  • Range: <6.x-2.4, <6.x-4.0-beta8

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.