First published: Tue Aug 14 2012(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SPIP SPIP | =1.9 | |
SPIP SPIP | =1.9.1 | |
SPIP SPIP | =1.9.2 | |
SPIP SPIP | =2.0 | |
SPIP SPIP | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2151 is rated as having a medium severity due to its impact on web security.
To fix CVE-2012-2151, update SPIP to version 1.9.2.o or newer for branch 1.9, 2.0.18 or newer for branch 2.0, and 2.1.13 or newer for branch 2.1.
The potential impacts of CVE-2012-2151 include unauthorized access and the execution of arbitrary web scripts or HTML.
CVE-2012-2151 affects SPIP versions 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13.
Yes, untrusted users can exploit CVE-2012-2151 to inject malicious scripts into the web application.