Unrated severityNVD Advisory· Published Aug 14, 2012· Updated Apr 29, 2026
CVE-2012-2072
CVE-2012-2072
Description
Cross-site scripting (XSS) vulnerability in the Share Buttons (AddToAny) module 6.x-3.x before 6.x-3.4 for Drupal allows remote authenticated users with the administer addtoany permission to inject arbitrary web script or HTML via unspecified vectors.
Affected products
5cpe:2.3:a:patrick_przybilla:addtoany:6.x-3.0:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:patrick_przybilla:addtoany:6.x-3.0:*:*:*:*:*:*:*
- cpe:2.3:a:patrick_przybilla:addtoany:6.x-3.1:*:*:*:*:*:*:*
- cpe:2.3:a:patrick_przybilla:addtoany:6.x-3.2:*:*:*:*:*:*:*
- cpe:2.3:a:patrick_przybilla:addtoany:6.x-3.3:*:*:*:*:*:*:*
- cpe:2.3:a:patrick_przybilla:addtoany:6.x-3.x:dev:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- drupal.org/node/1083664nvdPatch
- drupal.org/node/1506412nvdPatchVendor Advisory
- secunia.com/advisories/48615nvdVendor Advisory
- osvdb.org/80675nvd
- www.openwall.com/lists/oss-security/2012/04/07/1nvd
- www.securityfocus.com/bid/52777nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/74469nvd
News mentions
0No linked articles in our index yet.