CVE-2012-6720
11.02.2020, 20:15
Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/create, (2) location parameter to events/create, or (3) search parameter to widget/index/content_id/*.
Vendor | Product | Version |
---|---|---|
socialengine | socialengine | 𝑥 < 4.2.4 |
𝑥
= Vulnerable software versions