CVE-2012-2436: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter in a move or (2) minimize action to admin/adminindex.php; (3) the karmausername parameter to module.php in the karma module; (4) q1low, (5) q1high, (6) q2low, or (7) q2high parameter in a configure action to module.php in the captcha module; or (8) the edit parameter to module.php in the adminlanguage module.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2436?
CVE-2012-2436 has a severity rating that typically indicates the potential impact of cross-site scripting vulnerabilities, but the specific score can vary based on context.
How do I fix CVE-2012-2436?
To fix CVE-2012-2436, you should upgrade Pligg CMS to version 1.2.2 or later, where the vulnerabilities have been addressed.
What types of attacks are possible with CVE-2012-2436?
CVE-2012-2436 can allow attackers to execute arbitrary web scripts or HTML, potentially leading to data theft or user session hijacking.
Is my version of Pligg CMS affected by CVE-2012-2436?
If you are using Pligg CMS versions before 1.2.2, your installation is vulnerable to CVE-2012-2436.
How can I protect my website from CVE-2012-2436?
To protect your website from CVE-2012-2436, ensure you're running the latest version of Pligg CMS and regularly check for security updates.