PT-2023-9939 · Unknown · Ahmyi Rivettracker
Ahmyi
·
Published
2023-01-03
·
Updated
2024-05-17
·
CVE-2012-10002
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ahmyi RivetTracker (affected versions not specified)
Description
A vulnerability was found in ahmyi RivetTracker, affecting the function
changeColor of the file css.php. The manipulation of the argument set css leads to cross-site scripting. The attack can be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch named 45a0f33876d58cb7e4a0f17da149e58fc893b858. As a temporary workaround, consider disabling the
changeColor function until a patch is available. Restrict access to the vulnerable file css.php to minimize the risk of exploitation. Avoid using the argument set css in the affected function until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ahmyi Rivettracker