PT-2006-3202 · Tyro · Tyrocms

Nomenumbra

+1

·

Published

2006-05-05

·

Updated

2018-10-18

·

CVE-2006-2234

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TyroCMS version beta 1.0
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved through various means, including using a javascript URI in an img BBCode tag, or a JavaScript event in a url BBCode tag or color BBCode tag.
Recommendations For TyroCMS version beta 1.0, consider disabling the use of BBCode tags, specifically img, url, and color, until a fix is available to prevent the injection of arbitrary web script or HTML. Restrict access to these features to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2234

Affected Products

Tyrocms