VWE-2013-0012 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2013-0012
This page is a chapter in Info Known Vulnerabilities

This page has been seen 155,828 times.

    • Created by on
      Last updated by on
Common NameIdentity Theft Vulnerability
VWE-IDVWE-2013-0012
Related ReportNone
SeverityHIGH
Exploit DifficultyDifficult
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionHTML/Javascript injection
DiscoveredApril 7, 2013
ResolvedApril 8, 2013
Patches Available4.0.0 Alpha 5
WorkaroundUpdate all areas so that HTML is not allowed in comments.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.