CVE-2012-1652: XSS
Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "the vocabulary's help text."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1652?
CVE-2012-1652 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2012-1652?
To resolve CVE-2012-1652, update the Hierarchical Select module to version 6.x-3.8 or later.
Who is affected by CVE-2012-1652?
CVE-2012-1652 affects Drupal users who have installed specific vulnerable versions of the Hierarchical Select module.
What can attackers do with CVE-2012-1652?
Attackers can exploit CVE-2012-1652 to inject arbitrary web script or HTML if they have admin taxonomy permissions.
When was CVE-2012-1652 published?
CVE-2012-1652 was published in 2012 and affects versions before 6.x-3.8 of the Hierarchical Select module.