CVE-2012-2071

Geoff Davies Contact Forms - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Contact Forms module 6.x-1.x before 6.x-1.13 for Drupal when the core contact form is enabled, allows remote authenticated users with the administer site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0034
EPSS Percentile 56.0%

Classification

CWE
CWE-79
Status published

Affected Products (14)

geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
geoff_davies/contact_forms
n/a/n/a

Timeline

Published Aug 14, 2012
Tracked Since Feb 18, 2026