PT-2023-10252 · Unknown · Tinymighty Wikiseo

21Tinymighty

·

Published

2023-02-06

·

Updated

2024-05-17

·

CVE-2015-10073

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions tinymighty WikiSEO version 1.2.1
Description A vulnerability was found in tinymighty WikiSEO, affecting the function modifyHTML of the file WikiSEO.body.php of the component Meta Property Tag Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For tinymighty WikiSEO version 1.2.1, upgrade to version 1.2.2 to address this issue. As a temporary workaround, consider disabling the modifyHTML function until the patch is applied. Restrict access to the Meta Property Tag Handler component to minimize the risk of exploitation. Avoid using the argument content in the affected component until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2015-10073
GHSA-84MM-PRJG-49XM

Affected Products

Tinymighty Wikiseo