First published: Thu Feb 02 2012(Updated: )
Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of the user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TWiki | ||
TWiki | =5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0979 has a medium severity rating due to the potential for cross-site scripting attacks.
To fix CVE-2012-0979, update TWiki to a version that is patched against this XSS vulnerability.
CVE-2012-0979 can be exploited to perform cross-site scripting attacks where an attacker can inject malicious scripts.
CVE-2012-0979 affects multiple versions of TWiki, including version 5.1.1 and earlier releases.
Check if your TWiki installation allows for unsanitized input in the organization field of user profiles, as this indicates vulnerability to CVE-2012-0979.