2.1 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:S/C:N/I:P/A:N
0.967 High
EPSS
Percentile
99.7%
CVE: CVE-2012-2711
This module enables you to display the terms (and optionally nodes) under categories.
The module doesn’t sufficiently sanitize user supplied text in the taxonomy information.
This vulnerability is mitigated by the fact that an attacker must have a role with permissions to create or edit taxonomy terms.
The 6.x-2.x branch is not affected.
Drupal core is not affected. If you do not use the contributed Taxonomy List module, there is nothing you need to do.
Install the latest version:
Also see the Taxonomy List project page.
drupal.org/contact
drupal.org/node/1595396
drupal.org/node/815066
drupal.org/project/taxonomy_list
drupal.org/security-team
drupal.org/security-team/risk-levels
drupal.org/security/secure-configuration
drupal.org/user/101412
drupal.org/user/181798
drupal.org/user/395439
drupal.org/user/96647
drupal.org/writing-secure-code