CVE-2012-2066: XSS
Cross-site scripting (XSS) vulnerability in the FCKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal allows remote authenticated users or remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2066?
CVE-2012-2066 is classified as a high-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-2066?
To fix CVE-2012-2066, update the FCKeditor module to version 6.x-2.3 or later and the CKEditor module to version 6.x-1.9 or later for Drupal.
Who is affected by CVE-2012-2066?
CVE-2012-2066 affects users of the FCKeditor module and CKEditor module for Drupal versions 6.x-2.x before 6.x-2.3 and 6.x-1.x before 6.x-1.9.
What type of vulnerability is CVE-2012-2066?
CVE-2012-2066 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2012-2066 be exploited by unauthenticated users?
No, CVE-2012-2066 requires remote authenticated users or attackers to exploit the vulnerability.