CVE-2012-0914: XSS
Cross-site scripting (XSS) vulnerability in displayrenderers/panelsrenderereditor.class.php in the admin view in the Panels module 6.x-2.x before 6.x-3.10 and 7.x-3.x before 7.x-3.0 for Drupal allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the Region title.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0914?
CVE-2012-0914 is classified as a medium severity vulnerability due to its potential for exploitation via Cross-site scripting (XSS).
How do I fix CVE-2012-0914?
To fix CVE-2012-0914, upgrade the Panels module to version 6.x-3.10 or 7.x-3.0 or later.
Who is affected by CVE-2012-0914?
CVE-2012-0914 affects remote authenticated users with specific privileges in the Panels module for Drupal versions prior to the fixed releases.
What are the implications of CVE-2012-0914?
CVE-2012-0914 allows attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or site defacement.
Which versions of the Panels module are vulnerable to CVE-2012-0914?
CVE-2012-0914 affects Panels module versions 6.x-2.x prior to 6.x-3.10 and 7.x-3.x prior to 7.x-3.0.