CVE-2012-1789
19.03.2012, 18:55
Multiple cross-site scripting (XSS) vulnerabilities in Kongreg8 1.7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) surname or (2) firstname parameters to modules/members/addmember.php; or (3) groupdescription or (4) groupname parameters to modules/groups/addgroupform.php.
Vendor | Product | Version |
---|---|---|
tskynet | kongreg8 | 1.7.3 |
𝑥
= Vulnerable software versions
References