CVE-2012-5705

Drupal Hotblocks <6.x-1.8 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script or HTML via the "block names."

Scores

EPSS 0.0023
EPSS Percentile 45.7%

Details

CWE
CWE-79
Status published
Products (5)
justin_dodge/hotblocks
justin_dodge/hotblocks
justin_dodge/hotblocks
justin_dodge/hotblocks
n/a/n/a
Published Nov 01, 2012
Tracked Since Feb 18, 2026