CVE-2012-2768: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the topic administration page in the RTFM extension 2.0.4 through 2.4.3 for Best Practical Solutions RT allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2768?
CVE-2012-2768 is considered a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2012-2768?
To fix CVE-2012-2768, upgrade the RTFM extension to version 2.4.4 or later, as it contains the necessary patches for this vulnerability.
What software is affected by CVE-2012-2768?
CVE-2012-2768 affects RTFM extension versions 2.0.4 through 2.4.3 for Best Practical Solutions Request Tracker.
Can CVE-2012-2768 be exploited remotely?
Yes, CVE-2012-2768 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.
What are the potential impacts of CVE-2012-2768?
The potential impacts of CVE-2012-2768 include unauthorized access to user sessions, data theft, or defacement of web pages.