Vulnerability Description
Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotx | Pivotx | <= 2.3.2 |
Related Weaknesses (CWE)
References
- http://pivot-weblog.svn.sourceforge.net/viewvc/pivot-weblog?view=revision&revisi
- http://pivot-weblog.svn.sourceforge.net/viewvc/pivot-weblog?view=revision&revisi
- http://pivotx.net/page/security
- http://www.securityfocus.com/bid/53434
- https://www.htbridge.com/advisory/HTB23087Exploit
- http://pivot-weblog.svn.sourceforge.net/viewvc/pivot-weblog?view=revision&revisi
- http://pivot-weblog.svn.sourceforge.net/viewvc/pivot-weblog?view=revision&revisi
- http://pivotx.net/page/security
- http://www.securityfocus.com/bid/53434
- https://www.htbridge.com/advisory/HTB23087Exploit
FAQ
What is CVE-2012-2274?
CVE-2012-2274 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in pivotx/ajaxhelper.php in PivotX 2.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the file parameter.
How severe is CVE-2012-2274?
CVE-2012-2274 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2274?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotx Pivotx.