CVE-2012-0984: XSS
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) touserid parameter to modules/pm/pmlite.php or the (2) currentfile, (3) imgcatid, or (4) target parameter to class/xoopseditor/tinymce/tinymce/jscripts/tinymce/plugins/xoopsimagemanager/xoopsimagebrowser.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0984?
CVE-2012-0984 is classified as having a medium severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-0984?
To fix CVE-2012-0984, upgrade XOOPS to version 2.5.5 or later, which addresses these vulnerabilities.
What are the affected components in CVE-2012-0984?
CVE-2012-0984 affects the modules/pm/pmlite.php file and several parameters in the tinymce JavaScript editor.
Who can be impacted by CVE-2012-0984?
Remote attackers can exploit CVE-2012-0984 to inject arbitrary web scripts or HTML into affected XOOPS installations.
Is CVE-2012-0984 specific to a certain version of XOOPS?
Yes, CVE-2012-0984 specifically affects XOOPS versions prior to 2.5.5.