CVE-2012-2381

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
VendorProductVersion
apacheroller
𝑥
≤ 5.0
apacheroller
0.9.5
apacheroller
0.9.6
apacheroller
0.9.6.3
apacheroller
0.9.6.4
apacheroller
0.9.7
apacheroller
0.9.7.1
apacheroller
0.9.7.2
apacheroller
0.9.8
apacheroller
0.9.8.1
apacheroller
0.9.8.2
apacheroller
0.9.9
apacheroller
1.0
apacheroller
1.0:rc1
apacheroller
1.0:rc2
apacheroller
1.0.1
apacheroller
1.1
apacheroller
1.1.1
apacheroller
1.1.2
apacheroller
1.2
apacheroller
1.3
apacheroller
2.0
apacheroller
2.0.1
apacheroller
2.0.2
apacheroller
2.1
apacheroller
2.1.1
apacheroller
2.3
apacheroller
3.0
apacheroller
3.1
apacheroller
4.0
apacheroller
4.0.1
𝑥
= Vulnerable software versions