{"api_version":"1","generated_at":"2026-07-23T14:50:18+00:00","cve":"CVE-2010-4813","urls":{"html":"https://cve.report/CVE-2010-4813","api":"https://cve.report/api/cve/CVE-2010-4813.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-4813","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-4813"},"summary":{"title":"CVE-2010-4813","description":"Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-07-08 22:55:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"3.5","severity":"","vector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/44780","name":"http://www.securityfocus.com/bid/44780","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Drupal Category tokens Module Vocabulary Names HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://drupal.org/node/968176","name":"http://drupal.org/node/968176","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SA-CONTRIB-2010-102 - Category tokens - Cross Site Scripting | drupal.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63203","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63203","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/69145","name":"http://osvdb.org/69145","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/42168","name":"http://secunia.com/advisories/42168","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-4813","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-4813","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"4813","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"category_tokens_project","cpe5":"category_tokens","cpe6":"6.x-1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"drupal","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"4813","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"drupal","cpe5":"drupal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:02:29.576Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"42168","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42168"},{"name":"69145","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/69145"},{"name":"category-tokens-vocabulary-names-xss(63203)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63203"},{"name":"44780","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/44780"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://drupal.org/node/968176"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-11-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"42168","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42168"},{"name":"69145","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/69145"},{"name":"category-tokens-vocabulary-names-xss(63203)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63203"},{"name":"44780","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/44780"},{"tags":["x_refsource_CONFIRM"],"url":"http://drupal.org/node/968176"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-4813","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"42168","refsource":"SECUNIA","url":"http://secunia.com/advisories/42168"},{"name":"69145","refsource":"OSVDB","url":"http://osvdb.org/69145"},{"name":"category-tokens-vocabulary-names-xss(63203)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63203"},{"name":"44780","refsource":"BID","url":"http://www.securityfocus.com/bid/44780"},{"name":"http://drupal.org/node/968176","refsource":"CONFIRM","url":"http://drupal.org/node/968176"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-4813","datePublished":"2011-07-08T22:00:00.000Z","dateReserved":"2011-07-08T00:00:00.000Z","dateUpdated":"2024-08-07T04:02:29.576Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-07-08 22:55:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:category_tokens_project:category_tokens:6.x-1.0:*:*:*:*:drupal:*:*","matchCriteriaId":"0E4B85C4-9874-4436-BFA2-B17BE026949E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*","matchCriteriaId":"799CA80B-F3FA-4183-A791-2071A7DA1E54"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"4813","Ordinal":"1","Title":"CVE-2010-4813","CVE":"CVE-2010-4813","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"4813","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the Category Tokens module 6.x before 6.x-1.1 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML by editing or creating vocabulary names, which are not properly handled in token help.","Type":"Description","Title":"CVE-2010-4813"},{"CveYear":"2010","CveId":"4813","Ordinal":"2","NoteData":"2011-07-08","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"4813","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}