peter bassill · operator
$ cve CVE-2012-2909 JSON

CVE-2012-2909 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Viscacha 0.8.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) text field in the Private Messages System, (2) Bad Word field in Zensur, or (3) Portal or (4) Topic field in Kommentar.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS1.61% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2012-05-21
Last modified2026-06-16

Affected (1)

VendorProduct
viscachaviscacha

Public exploits

SourceTitleDate
exploit-dbViscacha Forum CMS 0.8.1.1 - Multiple Vulnerabilities2012-05-13

References

→ the Explorer  ·  watch your stack  ·  NVD