CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
Percentile
99.7%
This module, an add-on for Drupal Commerce, allows site builders to place one or more nodes in one of the checkout phases of an order.
The module doesn’t sufficiently confirm the intent of a site builder when taking certain administrative operations. This could allow an attacker to trick an administrator into unknowingly enabling/disabling a Commerce extra panes pane.
CVE: CVE-2012-5542
Drupal core is not affected. If you do not use the contributed Commerce extra panes module, there is nothing you need to do.
Install the latest version:
Also see the Commerce extra panes project page.