CVE-2012-1640: XSS
Published Sep 19, 2012
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.
Affected Software
3 affected components
Alquimia Managesite=6.x-1.0
Alquimia Managesite=6.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Event History
Sep 19, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1640?
The severity of CVE-2012-1640 is classified as low with a score of 2.1.
2
How do I fix CVE-2012-1640?
To fix CVE-2012-1640, apply the patch available for the Managesite module version 6.x-1.x before 6.1-1.1.
3
What types of vulnerabilities are present in CVE-2012-1640?
CVE-2012-1640 contains multiple cross-site scripting (XSS) vulnerabilities.
4
Who is impacted by CVE-2012-1640?
CVE-2012-1640 impacts remote authenticated users with 'administer managesite' permissions.
5
What actions can lead to exploitation of CVE-2012-1640?
Exploitation of CVE-2012-1640 can occur when adding or updating a category using the title parameter.