CVE-2012-2300

Ubercart - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal allow remote authenticated users with the administer product classes permission to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0047
EPSS Percentile 64.4%

Classification

CWE
CWE-79
Status published

Affected Products (35)

ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
ubercart/ubercart
... and 20 more

Timeline

Published Aug 14, 2012
Tracked Since Feb 18, 2026