CVE-2012-2711: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy List module 6.x-1.x before 6.x-1.4 for Drupal allow remote authenticated users with create or edit taxonomy terms permissions to inject arbitrary web script or HTML via vectors related to taxonomy information.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2711?
CVE-2012-2711 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-2711?
To fix CVE-2012-2711, upgrade the Taxonomy List module to version 6.x-1.4 or later.
Who is affected by CVE-2012-2711?
CVE-2012-2711 affects remote authenticated users who have create or edit taxonomy terms permissions.
What is the impact of CVE-2012-2711?
The impact of CVE-2012-2711 allows attackers to inject arbitrary web scripts or HTML into the application.
Which software versions are vulnerable to CVE-2012-2711?
Vulnerable versions of the Taxonomy List module include 6.x-1.0 through 6.x-1.3.