CVE-2012-2298: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) "user names in page titles" and (2) "autocomplete callbacks."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2298?
CVE-2012-2298 has a medium severity rating due to the potential for remote attackers to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2012-2298?
To fix CVE-2012-2298, you should update the RealName module to version 6.x-1.5 or later.
What versions of RealName are affected by CVE-2012-2298?
CVE-2012-2298 affects RealName module versions prior to 6.x-1.5, including versions 6.x-1.0 through 6.x-1.4.
What are the attack vectors for CVE-2012-2298?
The attack vectors for CVE-2012-2298 include user names in page titles and autocomplete callbacks.
Who can be impacted by CVE-2012-2298?
Remote attackers can exploit CVE-2012-2298 to inject arbitrary web scripts or HTML, potentially impacting users of the affected Drupal sites.