CVE-2012-1652

WIM Leers Hierarchical Select - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "the vocabulary's help text."

Scores

EPSS 0.0027
EPSS Percentile 50.0%

Classification

CWE
CWE-79
Status published

Affected Products (13)

wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wim_leers/hierarchical_select
wimleers/hierarchical_select
wimleers/hierarchical_select
wimleers/hierarchical_select
n/a/n/a

Timeline

Published Sep 19, 2012
Tracked Since Feb 18, 2026