Cross-Site Scripting Vulnerability in Ticketyboo News Ticker for Drupal
CVE-2012-2059

Currently unrated

Key Information:

Vendor
CVE Published:
17 September 2012

What is CVE-2012-2059?

A cross-site scripting (XSS) flaw exists within the Ticketyboo News Ticker module for Drupal, which enables remote attackers to inject arbitrary web scripts or HTML through unspecified input vectors. This vulnerability can be exploited to execute malicious scripts in the context of affected users, potentially leading to unauthorized access, data theft, or other harmful consequences.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.