PT-2023-9941 · Drupal · Backdrop-Contrib Basic Cart
Published
2023-01-11
·
Updated
2024-05-17
·
CVE-2012-10004
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
backdrop-contrib Basic Cart versions prior to 1.x-1.1.1
Description
A vulnerability was found in backdrop-contrib Basic Cart on Drupal, classified as problematic. It affects the function
basic cart checkout form submit of the file basic cart.cart.inc, leading to cross-site scripting. The attack can be launched remotely.Recommendations
For versions prior to 1.x-1.1.1, upgrade to version 1.x-1.1.1 to address this issue. As a temporary workaround, consider disabling the
basic cart checkout form submit function until the patch is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backdrop-Contrib Basic Cart