CVE-2012-0979: XSS
Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0979?
CVE-2012-0979 has a medium severity rating due to the potential for cross-site scripting attacks.
How do I fix CVE-2012-0979?
To fix CVE-2012-0979, update TWiki to a version that is patched against this XSS vulnerability.
What types of attacks can exploit CVE-2012-0979?
CVE-2012-0979 can be exploited to perform cross-site scripting attacks where an attacker can inject malicious scripts.
Which versions of TWiki are affected by CVE-2012-0979?
CVE-2012-0979 affects multiple versions of TWiki, including version 5.1.1 and earlier releases.
How can I determine if my TWiki installation is vulnerable to CVE-2012-0979?
Check if your TWiki installation allows for unsanitized input in the organization field of user profiles, as this indicates vulnerability to CVE-2012-0979.