CVE-2012-4469
Simon Rycroft Hashcash - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Hashcash module 6.x-2.x before 6.x-2.6 and 7.x-2.x before 7.x-2.2 for Drupal, when "Log failed hashcash" is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid token, which is not properly handled when administrators use the Database logging module.
Scores
EPSS
0.0036
EPSS Percentile
57.8%
Details
CWE
CWE-79
Status
published
Products (9)
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
simon_rycroft/hashcash
n/a/n/a
Published
Nov 30, 2012
Tracked Since
Feb 18, 2026