CVE-2010-3841: XSS
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3841?
CVE-2010-3841 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2010-3841?
To fix CVE-2010-3841, upgrade to TWiki version 5.0.1 or later, where this vulnerability has been addressed.
What types of attacks can CVE-2010-3841 enable?
CVE-2010-3841 can enable remote attackers to inject arbitrary web script or HTML, potentially leading to stolen session cookies or site defacement.
Which versions of TWiki are affected by CVE-2010-3841?
CVE-2010-3841 affects TWiki versions prior to 5.0.1, including various versions from 2000-12-01 up to 4.3.2.
What are the affected components of CVE-2010-3841?
The affected components related to CVE-2010-3841 include the view script's rev parameter and the query string in the login script.