VULNERABILITY INTELLIGENCE

CVE-2012-2301

CVSS score6 MEDIUM
EPSS probability1.21%
CISA KEVNot currently listed
Published2014-11-16
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:S/C:P/I:P/A:P

Description

The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.

Weakness classification

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Primary references