First published: Tue Jun 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB PATIO 4.04 and earlier might allow remote attackers to inject arbitrary web script or HTML via a crafted cookie.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
KENT-WEB WEB PATIO | =4.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2637 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2012-2637, upgrade KENT-WEB WEB PATIO to version 4.05 or later.
CVE-2012-2637 allows remote attackers to inject arbitrary web script or HTML, potentially stealing user data or performing unwanted actions.
CVE-2012-2637 affects KENT-WEB WEB PATIO version 4.04 and earlier.
Yes, user data is at risk due to the potential for malicious code execution via XSS in CVE-2012-2637.