CVE-2012-1639
Commerce < 7.x-1.1 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in product/commerce_product.module in the Drupal Commerce module for Drupal before 7.x-1.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) sku or (2) title parameters.
References (7)
Scores
EPSS
0.0034
EPSS Percentile
56.0%
Classification
CWE
CWE-79
Status
published
Affected Products (15)
commerceguys/commerce
< 7.x-1.1
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
commerceguys/commerce
n/a/n/a
Timeline
Published
Oct 01, 2012
Tracked Since
Feb 18, 2026