CVE-2012-1657

Fourkitchens Block Class - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in block_class.module in the Block Class module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the class name.

Scores

EPSS 0.0026
EPSS Percentile 49.0%

Classification

CWE
CWE-79
Status published

Affected Products (15)

fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
fourkitchens/block_class
n/a/n/a

Timeline

Published Sep 18, 2012
Tracked Since Feb 18, 2026