CVE-2012-10004: Backdropcms Basic Cart

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was found in backdrop-contrib Basic Cart on Drupal. It has been classified as problematic. Affected is the function basic_cart_checkout_form_submit of the file basic_cart.cart.inc. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.x-1.1.1 is able to address this issue. The patch is identified as a10424ccd4b3b4b433cf33b73c1ad608b11890b4. It is recommended to upgrade the affected component. VDB-217950 is the identifier assigned to this vulnerability.

Affected products

  • Backdropcms Basic Cart: before 1.x-1.1.1 (fixed in 1.x-1.1.1)

Published 2023-01-11. Last modified 2026-06-16.