PT-2012-3183 · Elefant · Elefant Cms

Publicado

2012-08-26

·

Atualizado

2022-05-17

·

CVE-2012-1296

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Elefant CMS versions 1.0.x through 1.0.2-Beta Elefant CMS versions 1.1.x through 1.1.5-Beta
Description The issue allows remote attackers to inject arbitrary web script or HTML via the title or body parameter to the "admin/preview" endpoint. This can be exploited by sending malicious input to the vulnerable parameters, potentially leading to cross-site scripting (XSS) attacks.
Recommendations For Elefant CMS versions 1.0.x through 1.0.2-Beta, update to version 1.0.2-Beta or later. For Elefant CMS versions 1.1.x through 1.1.5-Beta, update to version 1.1.5-Beta or later. As a temporary workaround, consider restricting access to the apps/admin/handlers/preview.php file and the "admin/preview" endpoint to minimize the risk of exploitation. Avoid using the title and body parameters in the affected endpoint until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1296
GHSA-QJJQ-RCQ8-JW6J

Produtos afetados

Elefant Cms