Vulnerability Intelligence Report
CVE-2012-1646
Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.
No Active Exploit Signals
CVSS Base Score
4.3
MEDIUM
EPSS Probability:2.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| drupal | faq | 6.x-1.0, 6.x-1.1, 6.x-1.2, 6.x-1.3, 6.x-1.4, 6.x-1.5, 6.x-1.6, 6.x-1.7, 6.x-1.8, 6.x-1.9, 6.x-1.10, 6.x-1.11, 6.x-1.12, 6.x-1.x, 7x-1.x-rc1 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.388%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2012-03-12T00:00:00 |
| Published | 2012-09-25T23:00:00 |
| Patch Date | 2012-02-22 |
| Last Updated | 2024-08-06T19:01:02 |
Community Chatter & Buzz