CVE-2012-5559: XSS
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5559?
CVE-2012-5559 has a medium severity rating due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2012-5559?
To fix CVE-2012-5559, upgrade the Chaos Tool Suite (ctools) module to version 6.x-1.10 or later.
What types of users are affected by CVE-2012-5559?
CVE-2012-5559 affects remote authenticated users with permissions to submit or edit nodes in Drupal.
What is the impact of exploiting CVE-2012-5559?
Exploiting CVE-2012-5559 allows attackers to inject arbitrary web scripts or HTML, potentially compromising user data.
Is CVE-2012-5559 specific to certain versions of ctools?
Yes, CVE-2012-5559 specifically affects ctools versions 6.x-1.0 through 6.x-1.9.