CVE-2012-1627: XSS
Cross-site scripting (XSS) vulnerability in vudterm.module in the Vote Up/Down module 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via taxonomy terms.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1627?
CVE-2012-1627 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-1627?
To fix CVE-2012-1627, upgrade the Vote Up/Down module to version 6.x-2.8 or 6.x-3.1 or later.
Who is affected by CVE-2012-1627?
CVE-2012-1627 affects users running the Vote Up/Down module versions 6.x-2.x before 6.x-2.8 and 6.x-3.x before 6.x-3.1 in Drupal.
What are the implications of CVE-2012-1627 if exploited?
If exploited, CVE-2012-1627 allows remote authenticated users to inject arbitrary web scripts or HTML into the application.
Is there a patch available for CVE-2012-1627?
Yes, patches for CVE-2012-1627 are included in the newer versions of the Vote Up/Down module.