CVE-2012-2151: XSS
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2151?
CVE-2012-2151 is rated as having a medium severity due to its impact on web security.
How do I fix CVE-2012-2151?
To fix CVE-2012-2151, update SPIP to version 1.9.2.o or newer for branch 1.9, 2.0.18 or newer for branch 2.0, and 2.1.13 or newer for branch 2.1.
What are the potential impacts of CVE-2012-2151?
The potential impacts of CVE-2012-2151 include unauthorized access and the execution of arbitrary web scripts or HTML.
Which versions of SPIP are affected by CVE-2012-2151?
CVE-2012-2151 affects SPIP versions 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13.
Can untrusted users exploit CVE-2012-2151?
Yes, untrusted users can exploit CVE-2012-2151 to inject malicious scripts into the web application.