PT-2023-9941 · Drupal · Backdrop-Contrib Basic Cart

CVE-2012-10004

·

Published

2023-01-11

·

Updated

2024-05-17

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions backdrop-contrib Basic Cart versions prior to 1.x-1.1.1
Description A vulnerability was found in backdrop-contrib Basic Cart on Drupal, classified as problematic. It affects the function basic cart checkout form submit of the file basic cart.cart.inc, leading to cross-site scripting. The attack can be launched remotely.
Recommendations For versions prior to 1.x-1.1.1, upgrade to version 1.x-1.1.1 to address this issue. As a temporary workaround, consider disabling the basic cart checkout form submit function until the patch is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-10004

Affected Products

Backdrop-Contrib Basic Cart