First published: Mon Oct 22 2012(Updated: )
Cross-site scripting (XSS) vulnerability in admin/plugin-index.php in OpenX 2.8.10 before revision 81823 allows remote attackers to inject arbitrary web script or HTML via the parent parameter in an info action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open edX | =2.8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4989 is classified as a medium severity vulnerability due to its ability to allow cross-site scripting attacks.
To fix CVE-2012-4989, it is recommended to upgrade OpenX to a version later than 2.8.10, specifically after revision 81823.
The vulnerability CVE-2012-4989 specifically affects OpenX version 2.8.10.
CVE-2012-4989 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Remote attackers can exploit CVE-2012-4989 to perform cross-site scripting attacks through a crafted request to the vulnerable OpenX application.