CVE-2012-2381: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2381?
CVE-2012-2381 has a medium severity rating that allows remote authenticated users to exploit cross-site scripting vulnerabilities.
How do I fix CVE-2012-2381?
To mitigate CVE-2012-2381, upgrade Apache Roller to version 5.0.1 or later.
Who is affected by CVE-2012-2381?
CVE-2012-2381 affects all versions of Apache Roller prior to 5.0.1, particularly versions used by authenticated users with the blogger role.
What types of attacks are associated with CVE-2012-2381?
CVE-2012-2381 is associated with cross-site scripting (XSS) attacks where users can inject malicious scripts.
Is there a workaround for CVE-2012-2381 if I cannot upgrade?
If upgrading is not possible for CVE-2012-2381, consider disabling the blogger role or applying content security policies to reduce XSS risks.