CVE-2012-1899
17.09.2012, 20:55
Multiple cross-site scripting (XSS) vulnerabilities in webfolio/admin/users/edit in Webfolio CMS 1.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name, (2) Last name or (3) Email (required) fields.
| Vendor | Product | Version |
|---|---|---|
| nikola_posa | webfoliocms | 1.0.2 |
| nikola_posa | webfoliocms | 1.0.3 |
| nikola_posa | webfoliocms | 1.0.4 |
| nikola_posa | webfoliocms | 1.0.5 |
| nikola_posa | webfoliocms | 1.0.6 |
| nikola_posa | webfoliocms | 1.0.7 |
| nikola_posa | webfoliocms | 1.0.8 |
| nikola_posa | webfoliocms | 1.0.9 |
| nikola_posa | webfoliocms | 1.1.0 |
| nikola_posa | webfoliocms | 1.1.1 |
| nikola_posa | webfoliocms | 1.1.2 |
| nikola_posa | webfoliocms | 1.1.3 |
| nikola_posa | webfoliocms | 1.1.4 |
𝑥
= Vulnerable software versions
References