Vulnerability Description
Cross-site scripting (XSS) vulnerability in Kobe Beauty php-contact-form before 2016-05-18 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kobe-Beauty | Php-Contact-Form | < 2016-05-18 |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN85112513/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000070Third Party AdvisoryVDB EntryVendor Advisory
- http://www.kobe-beauty.co.jp/php-contact-form/Vendor Advisory
- https://github.com/kobebeauty/php-contact-form/commit/e7d094ca8ab15215c32d6fa04dPatch
- http://jvn.jp/en/jp/JVN85112513/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000070Third Party AdvisoryVDB EntryVendor Advisory
- http://www.kobe-beauty.co.jp/php-contact-form/Vendor Advisory
- https://github.com/kobebeauty/php-contact-form/commit/e7d094ca8ab15215c32d6fa04dPatch
FAQ
What is CVE-2016-1222?
CVE-2016-1222 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in Kobe Beauty php-contact-form before 2016-05-18 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
How severe is CVE-2016-1222?
CVE-2016-1222 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1222?
Check the references section above for vendor advisories and patch information. Affected products include: Kobe-Beauty Php-Contact-Form.