peter bassill · operator
$ cve CVE-2011-5025 JSON

CVE-2011-5025 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web script or HTML via (1) the tag parameter to editTag.yaws, (2) the index parameter to showOldPage.yaws, (3) the node parameter to allRefsToMe.yaws, or (4) the text parameter to editPage.yaws.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.66% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2011-12-29
Last modified2026-06-16

Affected (1)

VendorProduct
yawsyaws

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD