CVE-2012-4492

Isaac Sukin Shorten - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors to the (1) report or (2) Custom Services List page.

Scores

EPSS 0.0025
EPSS Percentile 48.3%

Details

CWE
CWE-79
Status published
Products (19)
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
... and 9 more
Published Oct 31, 2012
Tracked Since Feb 18, 2026