2.6 Low
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
0.967 High
EPSS
Percentile
99.7%
The Spambot module enables you to protect new user registrations from spammers using the database at stopforumspam.com.
Spambot doesn’t sufficiently sanitize API responses from stopforumspam.com when they are logged to the watchdog, allowing a potential XSS attack.
This vulnerability is mitigated by the fact that only stopforumspam.com (or someone pretending to be stopforumspam.com) can exploit it.
CVE: CVE-2012-6582
Drupal core is not affected. If you do not use the contributed Spambot module, there is nothing you need to do.
Install the latest version:
Also see the Spambot project page.
drupal.org/contact
drupal.org/node/1789084
drupal.org/node/1789086
drupal.org/project/spambot
drupal.org/security-team
drupal.org/security-team/risk-levels
drupal.org/security/secure-configuration
drupal.org/user/132729
drupal.org/user/36762
drupal.org/user/565562
drupal.org/user/91990
drupal.org/writing-secure-code