CVE-2012-4484: Trexart Campaignmonitor
Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in the administrative interface in the Campaign Monitor module before 6.x-2.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this refers to an issue in an independently developed Drupal module, and NOT an issue in the Campaign Monitor software itself (described on the campaignmonitor.com web site).
Affected products
- Trexart Campaignmonitor: up to and including 6.x-2.4; version 6.x-1.1 only; version 6.x-1.x-dev only; version 6.x-2.1 only; version 6.x-2.2 only; version 6.x-2.3 only; …
Published 2012-10-31. Last modified 2026-06-16.