{"id":"CVE-2012-1637","title":"Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.","summary":"Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"quick_tabs_project","product":"quick_tabs","affected":["quick_tabs = 6.x-2.0","quick_tabs = 6.x-3.0","quick_tabs = 7.x-3.0","quick_tabs = 7.x-3.1","quick_tabs = 7.x-3.2"],"published":"2019-11-21","updated":"2026-09-24","sourceUpdated":"2026-09-24T18:01:45.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2012-1637","references":[{"url":"http://www.openwall.com/lists/oss-security/2012/04/07/1","label":"secalert@redhat.com"},{"url":"https://www.drupal.org/node/1409476","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2012/04/07/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.drupal.org/node/1409476","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00528,"epssPercentile":0.422,"ingestedAt":"2026-09-24T18:49:36.695Z","slug":"CVE-2012-1637","body":"## Overview\n\nCross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.\n\n## Affected\n\n- `quick_tabs = 6.x-2.0`\n- `quick_tabs = 6.x-3.0`\n- `quick_tabs = 7.x-3.0`\n- `quick_tabs = 7.x-3.1`\n- `quick_tabs = 7.x-3.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":27,"depthScoreParts":{"impact":26.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}