CVE-2012-4469

Simon Rycroft Hashcash - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.

Scores

EPSS 0.0036
EPSS Percentile 57.8%

Details

CWE
CWE-79
Status published
Products (9)
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
n/a/n/a
Published Nov 30, 2012
Tracked Since Feb 18, 2026