CVE-2012-2067: Medium severity ckeditor vulnerability
Unspecified vulnerability in the CKeditor module 6.x-2.x before 6.x-2.3 and the CKEditor module 6.x-1.x before 6.x-1.9 and 7.x-1.x before 7.x-1.7 for Drupal, when the core PHP module is enabled, allows remote authenticated users or remote attackers to execute arbitrary PHP code via the text parameter to a text filter. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2067?
CVE-2012-2067 has a critical severity as it allows remote authenticated users to execute arbitrary PHP code.
How do I fix CVE-2012-2067?
Fix CVE-2012-2067 by updating the CKEditor module to version 6.x-2.3 or 6.x-1.9 or later.
Which versions of the CKEditor module are affected by CVE-2012-2067?
Versions before 6.x-2.3, 6.x-1.9, and 7.x-1.7 of the CKEditor module are vulnerable to CVE-2012-2067.
Can CVE-2012-2067 be exploited without authentication?
No, CVE-2012-2067 requires authentication to exploit the vulnerability.
What kind of attacks can be executed using the CVE-2012-2067 vulnerability?
Remote attackers can execute arbitrary PHP code through manipulated text parameters, potentially leading to unauthorized access or data compromise.