First published: Thu Jan 01 2015(Updated: )
Cross-site scripting (XSS) vulnerability in Spitfire CMS 1.0.436 allows remote attackers to inject arbitrary web script or HTML via a cms_username cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TIBCO Spotfire | =1.0436 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5303 is classified as a medium severity vulnerability.
To fix CVE-2011-5303, upgrade Spitfire CMS to a version that no longer includes the vulnerability.
CVE-2011-5303 allows attackers to perform cross-site scripting attacks, potentially leading to the theft of sensitive user information.
CVE-2011-5303 can be easily exploited by an attacker with basic knowledge of web scripting.
CVE-2011-5303 affects Spitfire CMS version 1.0.436.