CVE-2012-1652: Wim Leers Hierarchical Select

Low severity, CVSS 2.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Hierarchical Select module 6.x-3.x before 6.x-3.8 for Drupal allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via unspecified vectors related to "the vocabulary's help text."

Affected products

  • Wim Leers Hierarchical Select: version 6.x-3.0 only; version 6.x-3.1 only; version 6.x-3.2 only; version 6.x-3.3 only; version 6.x-3.4 only; version 6.x-3.5 only; …
  • Wimleers Hierarchical Select: version 6.x-3.0 only; version 6.x-3.1 only; version 6.x-3.x only

Published 2012-09-19. Last modified 2026-06-16.