CVE-2012-10004: backdrop-contrib Basic Cart basic_cart.cart.inc basic_cart_checkout_form_submit cross site scripting
A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basiccartcheckoutformsubmit of the file basiccart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.x-1.1.1 is able to address this issue. The patch is identified as a10424ccd4b3b4b433cf33b73c1ad608b11890b4. It is recommended to upgrade the affected component. VDB-217950 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2012-10004?
CVE-2012-10004 is a vulnerability found in backdrop-contrib Basic Cart on Drupal that allows for cross site scripting attacks.
How severe is CVE-2012-10004?
CVE-2012-10004 has a severity rating of medium with a CVSS score of 6.1.
Which software is affected by CVE-2012-10004?
The software affected by CVE-2012-10004 is backdrop-contrib Basic Cart with versions up to and excluding 1.x-1.1.1.
How can I fix CVE-2012-10004?
To fix CVE-2012-10004, it is recommended to upgrade to the latest version of backdrop-contrib Basic Cart.
Where can I find more information about CVE-2012-10004?
More information about CVE-2012-10004 can be found at the following references: [link1](https://github.com/backdrop-contrib/basic_cart/commit/a10424ccd4b3b4b433cf33b73c1ad608b11890b4), [link2](https://github.com/backdrop-contrib/basic_cart/releases/tag/1.x-1.1.1), [link3](https://vuldb.com/?ctiid.217950).