CVE-2012-0986: XSS
Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATHINFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0986?
CVE-2012-0986 is categorized as a high-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2012-0986?
To fix CVE-2012-0986, upgrade ImpressCMS to version 1.2.7 Final or 1.3.1 Final or later.
What versions of ImpressCMS are affected by CVE-2012-0986?
CVE-2012-0986 affects ImpressCMS versions 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final.
Can CVE-2012-0986 lead to data breaches?
Yes, CVE-2012-0986 can allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to data breaches.
What are the specific files affected by CVE-2012-0986?
Files affected by CVE-2012-0986 include notifications.php and modules/system/admin/images/browser.php among others.