CVE-2011-1838: XSS
Published May 20, 2011
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via the origurl parameter to a (1) view script or (2) login script.
Affected Software
20 affected components
Twiki TWiki=4.1.1
Twiki TWiki=4.0.1
Twiki TWiki=4.2.3
Twiki TWiki=4.2.4
Twiki TWiki=4.3.0
Twiki TWiki=4.3.2
Twiki TWiki=4.0.3
Twiki TWiki=4.0.4
Twiki TWiki=4.2.1
Twiki TWiki=4.2.0
Twiki TWiki=4.0.0
Twiki TWiki=4.5.0
Twiki TWiki=4.1.0
Twiki TWiki=4.3.1
Twiki TWiki=5.0.0
Twiki TWiki=4.2.2
Twiki TWiki<=5.0.1
Twiki TWiki=4.0.2
Twiki TWiki=4.0.5
Twiki TWiki=4.1.2
Remediation
Event History
May 20, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1838?
CVE-2011-1838 has been classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2011-1838?
To fix CVE-2011-1838, upgrade to TWiki version 5.0.2 or later to eliminate the vulnerabilities.
3
What are the potential impacts of CVE-2011-1838?
The potential impacts of CVE-2011-1838 include unauthorized script execution in the context of a user's browser, which can lead to data theft or session hijacking.
4
Which versions of TWiki are affected by CVE-2011-1838?
CVE-2011-1838 affects TWiki versions 4.0.0 through 5.0.1.
5
Can CVE-2011-1838 be exploited remotely?
Yes, CVE-2011-1838 can be exploited remotely by attackers using crafted URLs.