CVE-2012-1637
Executive Summary
Cross‑site scripting (XSS) in Drupal Quick Tabs module (6.x‑2.x <6.1, 6.x‑3.x <6.1, 7.x‑3.x <7.3) allows attackers to inject arbitrary scripts via unsanitized input, enabling session hijacking, defacement, or data theft. No patch in KEV. Mitigation: upgrade to 6.x‑2.1/6.x‑3.1/7.x‑3.3 or later, or apply module patch.
Authoritative CVE Metadata - CVSS Base Score: 4.8 (MEDIUM) - Published: 2019-11-21T23:15:11.607 - Last Modified: 2026-09-24T18:01:45.160
Original Description: Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
"Worry often gives a small thing a big shadow."
— Swedish proverb
Source: NVD