CVE-2012-1899

Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nikola_posa:webfoliocms:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:nikola_posa:webfoliocms:1.1.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-09-17 20:55

Updated : 2024-02-04 18:16


NVD link : CVE-2012-1899

Mitre link : CVE-2012-1899

CVE.ORG link : CVE-2012-1899


JSON object : View

Products Affected

nikola_posa

  • webfoliocms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')