← Back to CVE List
Vulnerability Intelligence Report

CVE-2012-1646

Multiple cross-site scripting (XSS) vulnerabilities in the FAQ module 6.x-1.x before 6.x-1.13 and 7.x-1.x-rc1 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via the (1) title parameter in faq.admin.inc or (2) detailed_question parameter in faq.module.

No Active Exploit Signals
CVSS Base Score
4.3
MEDIUM
EPSS Probability:2.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
drupal faq 6.x-1.0, 6.x-1.1, 6.x-1.2, 6.x-1.3, 6.x-1.4, 6.x-1.5, 6.x-1.6, 6.x-1.7, 6.x-1.8, 6.x-1.9, 6.x-1.10, 6.x-1.11, 6.x-1.12, 6.x-1.x, 7x-1.x-rc1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.388%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2012-03-12T00:00:00
Published2012-09-25T23:00:00
Patch Date2012-02-22
Last Updated2024-08-06T19:01:02

LINK COPIED TO CLIPBOARD