CVE-2012-4493: XSS
Published Nov 2, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer better revisions" permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected components
Roy Baxter Better Revisions=7.x-1.0
Roy Baxter Better Revisions=7.x-1.0-rc1
Roy Baxter Better Revisions=7.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Nov 2, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4493?
The severity of CVE-2012-4493 is rated as low, with a score of 2.1.
2
What does CVE-2012-4493 exploit?
CVE-2012-4493 exploits a cross-site scripting (XSS) vulnerability in the Better Revisions module for Drupal.
3
How do I fix CVE-2012-4493?
You can fix CVE-2012-4493 by applying the available patch for Better Revisions module version 7.x-1.1 or later.
4
Who is affected by CVE-2012-4493?
CVE-2012-4493 affects remote authenticated users who have the 'administer better revisions' permission.
5
What type of vulnerability is CVE-2012-4493?
CVE-2012-4493 is classified as a cross-site scripting (XSS) vulnerability.