CVE-2012-3800

Moshe Weitzman Organic Groups - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in og.js in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal, when used with the Vertical Tabs module, allows remote authenticated users to inject arbitrary web script or HTML via vectors related the group title.

Scores

EPSS 0.0030
EPSS Percentile 53.3%

Classification

CWE
CWE-79
Status published

Affected Products (9)

moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
moshe_weitzman/organic_groups
n/a/n/a

Timeline

Published Jun 27, 2012
Tracked Since Feb 18, 2026