SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2072

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

MEDIUM 6.8EPSS 4.18%

Does this matter?

Lower severity and a low EPSS score (4.18%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
4.18% probability · 90th percentile
CISA KEV
Not listed
Affected
mambo/mambo open source
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.