CVE-2012-1004: XSS
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1004?
CVE-2012-1004 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2012-1004?
To fix CVE-2012-1004, upgrade Foswiki to version 1.1.5 or later.
Who is affected by CVE-2012-1004?
CVE-2012-1004 affects remote authenticated users with CHANGE privileges in Foswiki versions prior to 1.1.5.
What type of vulnerability is CVE-2012-1004?
CVE-2012-1004 is a cross-site scripting (XSS) vulnerability that allows script injection.
Can CVE-2012-1004 be exploited by unauthenticated users?
No, CVE-2012-1004 requires authenticated users with CHANGE privileges to exploit the vulnerability.