PT-2012-3709 · Socialcms · Socialcms

Ivano Binetti

·

Published

2012-04-04

·

Updated

2017-08-29

·

CVE-2012-1982

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SocialCMS versions 1.0.2 and earlier
Description A cross-site scripting (XSS) issue allows remote authenticated users to inject arbitrary web script or HTML via the TR title parameter in an edit action.
Recommendations For SocialCMS versions 1.0.2 and earlier, avoid using the TR title parameter in the affected edit action until a fix is available. As a temporary workaround, consider restricting access to the my admin/admin1 list pages.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1982

Affected Products

Socialcms