First published: Fri Dec 21 2012(Updated: )
Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Concrete5 | =5.5.0 | |
Concrete5 | =5.5.1 | |
Concrete5 | =5.5.1 | |
Concrete5 | =5.5.2 | |
Concrete5 | =5.5.2 | |
Concrete5 | =5.5.2.1 | |
Concrete5 | =5.5.2.1 | |
Concrete5 | =5.6.0 | |
Concrete5 | =5.6.0.1 | |
Concrete5 | =5.6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-5181 is classified as having a moderate severity level due to its potential for exploiting cross-site scripting vulnerabilities.
To remediate CVE-2012-5181, upgrade to Concrete5 version 5.6.0.3 or later, which addresses this vulnerability.
CVE-2012-5181 affects Concrete5 versions 5.5.0 through 5.6.0.2, including specific builds for both English and Japanese.
CVE-2012-5181 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Users of affected Concrete5 versions are at risk of exploitation through the cross-site scripting vulnerability outlined in CVE-2012-5181.