CVE-2012-1630: XSS
Published Sep 20, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
2 affected components
Nestor Mata Cuthbert Taxonomy Navigator
Drupal Drupal
Event History
Sep 20, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1630?
The severity of CVE-2012-1630 is rated as low with a score of 2.1.
2
What type of vulnerability is CVE-2012-1630?
CVE-2012-1630 is a cross-site scripting (XSS) vulnerability.
3
Who is affected by CVE-2012-1630?
Remote authenticated users with specific permissions in the Taxonomy Navigator module for Drupal are affected by CVE-2012-1630.
4
How can I fix CVE-2012-1630?
To fix CVE-2012-1630, ensure that you update the Taxonomy Navigator module for Drupal to the latest version.
5
What can attackers do with CVE-2012-1630?
Attackers can inject arbitrary web scripts or HTML through unspecified vectors due to CVE-2012-1630.