peter bassill · operator
$ cve CVE-2011-2201 JSON

CVE-2011-2201 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS6.9% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2011-09-14
Last modified2026-06-16

Affected (2)

VendorProduct
mark stosbergdata\
perlperl

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD