CVE-2012-2300: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal allow remote authenticated users with the administer product classes permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2300?
CVE-2012-2300 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-2300?
To fix CVE-2012-2300, upgrade to Ubercart version 6.x-2.8 or 7.x-3.1 or later, which addresses the vulnerabilities.
Who is affected by CVE-2012-2300?
CVE-2012-2300 affects users of Ubercart versions 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 with the administer product classes permission.
What types of attacks can be executed through CVE-2012-2300?
CVE-2012-2300 allows attackers to execute cross-site scripting (XSS) attacks, injecting arbitrary web script or HTML into the application.
Is there a workaround for CVE-2012-2300?
There are no effective workarounds for CVE-2012-2300; upgrading to a patched version is the best mitigation strategy.