Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

21Tinymighty

#26735de 53,633
9.6CVSS total
Vulnerabilidades · 1
PT-2023-10252
9.6
2023-02-06
Unknown · Tinymighty Wikiseo · CVE-2015-10073
**Name of the Vulnerable Software and Affected Versions** tinymighty WikiSEO version 1.2.1 **Description** A vulnerability was found in tinymighty WikiSEO, affecting the function `modifyHTML` of the file WikiSEO.body.php of the component Meta Property Tag Handler. The manipulation of the argument `content` leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. **Recommendations** For tinymighty WikiSEO version 1.2.1, upgrade to version 1.2.2 to address this issue. As a temporary workaround, consider disabling the `modifyHTML` function until the patch is applied. Restrict access to the Meta Property Tag Handler component to minimize the risk of exploitation. Avoid using the argument `content` in the affected component until the issue is resolved.