CVE-2012-5559

Drupal ctools <6.x-1.10 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web script or HTML via the page title.

Scores

EPSS 0.0019
EPSS Percentile 41.0%

Details

CWE
CWE-79
Status published
Products (20)
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
chaos_tool_suite_project/ctools
... and 10 more
Published Dec 03, 2012
Tracked Since Feb 18, 2026