Multiple cross-site scripting (XSS) vulnerabilities in modules_v3/googlemap/wt_v3_street_view.php in webtrees before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) map, (2) streetview, or (3) reset parameter.
References
Configurations
History
No history.
Information
Published : 2015-01-13 11:59
Updated : 2024-02-04 18:35
NVD link : CVE-2014-100006
Mitre link : CVE-2014-100006
CVE.ORG link : CVE-2014-100006
JSON object : View
Products Affected
webtrees
- webtrees
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')