PT-2009-1436 · Tribiq · Tribiq Cms Community
Published
2009-01-23
·
Updated
2012-10-24
·
CVE-2008-5961
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Tribiq CMS Community versions 5.0.10B through 5.0.11E
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
cID parameter in a document action. This could potentially lead to unauthorized access or control of user sessions.Recommendations
For versions 5.0.10B through 5.0.11E, avoid using the
cID parameter in the document action until a fix is available. As a temporary workaround, consider restricting access to the index.php file to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tribiq Cms Community