CVE-2012-1639

Commerce < 7.x-1.1 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.

Scores

EPSS 0.0034
EPSS Percentile 56.0%

Classification

CWE
CWE-79
Status published

Affected Products (15)

commerceguys/commerce < 7.x-1.1
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
n/a/n/a

Timeline

Published Oct 01, 2012
Tracked Since Feb 18, 2026