CVE-2012-4496: XSS
Published Oct 31, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the Custom Publishing Options module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "administer nodes" permission to inject arbitrary web script or HTML via the status labels parameter.
Affected Software
7 affected components
Inclind Custom Pub=6.x-1.0
Inclind Custom Pub=6.x-1.0-beta1
Inclind Custom Pub=6.x-1.1
Inclind Custom Pub=6.x-1.2
Inclind Custom Pub=6.x-1.3
Inclind Custom Pub=6.x-1.x-dev
Drupal Drupal
Remediation
Patch Available
Event History
Oct 31, 2012
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4496?
The severity of CVE-2012-4496 is rated low at 2.1.
2
How do I fix CVE-2012-4496?
To fix CVE-2012-4496, you should apply the available patch for the Custom Publishing Options module.
3
What type of vulnerability is CVE-2012-4496?
CVE-2012-4496 is a Cross-site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2012-4496?
Remote authenticated users with the 'administer nodes' permission in Drupal are affected by CVE-2012-4496.
5
What can attackers do with CVE-2012-4496?
Attackers can inject arbitrary web scripts or HTML via the status labels parameter due to CVE-2012-4496.