peter bassill · operator
$ cve CVE-2009-2145 JSON

CVE-2009-2145 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.6% (pctl 74)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.56% — more likely to be exploited than 74% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2009-06-22
Last modified2026-06-16

Affected (1)

VendorProduct
panthatranslucid

Public exploits

SourceTitleDate
exploit-dbTransLucid 1.75 - Multiple Vulnerabilities2009-06-12

References

→ the Explorer  ·  watch your stack  ·  NVD