CVE-2012-0976

Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained from third party information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:silverstripe:silverstripe:2.4.6:*:*:*:*:*:*:*

History

21 Nov 2024, 01:36

Type Values Removed Values Added
References () http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13 - () http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13 -
References () http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7 - () http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7 -
References () http://osvdb.org/78677 - () http://osvdb.org/78677 -
References () http://packetstormsecurity.org/files/view/109210/silverstripecmspage-xss.txt - Exploit () http://packetstormsecurity.org/files/view/109210/silverstripecmspage-xss.txt - Exploit
References () http://secunia.com/advisories/47812 - Vendor Advisory () http://secunia.com/advisories/47812 - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2012/04/30/3 - () http://www.openwall.com/lists/oss-security/2012/04/30/3 -
References () http://www.securityfocus.com/bid/51761 - () http://www.securityfocus.com/bid/51761 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/72820 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/72820 -
References () https://github.com/silverstripe/sapphire/commit/252e187 - () https://github.com/silverstripe/sapphire/commit/252e187 -
References () https://github.com/silverstripe/sapphire/commit/475e077 - () https://github.com/silverstripe/sapphire/commit/475e077 -
References () https://github.com/silverstripe/sapphire/commit/5fe7091 - () https://github.com/silverstripe/sapphire/commit/5fe7091 -

Information

Published : 2012-02-02 17:55

Updated : 2024-11-21 01:36


NVD link : CVE-2012-0976

Mitre link : CVE-2012-0976

CVE.ORG link : CVE-2012-0976


JSON object : View

Products Affected

silverstripe

  • silverstripe
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')