CVE-2012-1019: XSS
Multiple cross-site scripting (XSS) vulnerabilities in XWiki Enterprise 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) XWiki.XWikiCommentscomment parameter to xwiki/bin/commentadd/Main/WebHome, (2) XWiki.XWikiUsers0company parameter when editing a user profile, or (3) projectVersion parameter to xwiki/bin/view/DownloadCode/DownloadFeedback. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1019?
CVE-2012-1019 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2012-1019?
To fix CVE-2012-1019, upgrade to a patched version of XWiki Enterprise that addresses these cross-site scripting vulnerabilities.
What types of attacks can CVE-2012-1019 be exploited for?
CVE-2012-1019 can be exploited to execute arbitrary web scripts or HTML, allowing for session hijacking or phishing attacks.
Which software versions are affected by CVE-2012-1019?
CVE-2012-1019 specifically affects XWiki Enterprise version 3.4.
Can CVE-2012-1019 affect user data security?
Yes, CVE-2012-1019 poses a risk to user data security by enabling attackers to inject malicious scripts that could compromise user sessions.