PT-2012-5829 · Concrete5 · Concrete5
Yuji Tounai
·
Published
2012-12-21
·
Updated
2022-05-17
·
CVE-2012-5181
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
concrete5 Japanese versions 5.5.1 through 5.5.2.1
concrete5 English versions 5.5.0 through 5.6.0.2
Description
The issue is related to a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML. This can be achieved via unspecified vectors.
Recommendations
For concrete5 Japanese versions 5.5.1 through 5.5.2.1, update to a version outside of this range to resolve the issue.
For concrete5 English versions 5.5.0 through 5.6.0.2, update to a version outside of this range to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Concrete5