CVE-2010-1195: XSS
Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1195?
CVE-2010-1195 is classified with a medium severity level, primarily due to its potential for cross-site scripting vulnerabilities.
How do I fix CVE-2010-1195?
To mitigate CVE-2010-1195, upgrade to ikiwiki version 2.53.5 or higher for 2.x, or 3.20100312 or higher for 3.x.
What types of systems are affected by CVE-2010-1195?
CVE-2010-1195 affects ikiwiki versions prior to 2.53.5 in the 2.x branch and versions prior to 3.20100312 in the 3.x branch.
What kind of attack does CVE-2010-1195 enable?
CVE-2010-1195 enables remote attackers to inject arbitrary web scripts or HTML through crafted data:image/svg+xml URIs.
Is there a patch available for CVE-2010-1195?
Yes, a patch is included in the updated versions of ikiwiki, which resolves the vulnerabilities associated with CVE-2010-1195.