CVE-2012-4492
Isaac Sukin Shorten - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Shorten URLs module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors to the (1) report or (2) Custom Services List page.
References (6)
Scores
EPSS
0.0025
EPSS Percentile
48.3%
Details
CWE
CWE-79
Status
published
Products (19)
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
isaac_sukin/shorten
... and 9 more
Published
Oct 31, 2012
Tracked Since
Feb 18, 2026