VulnerabilityModified
CVE-2007-4281
Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.
MEDIUM 4.3EPSS 1.26%
Does this matter?
Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.26% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- knowledgetree/open source
- Source
- cve@mitre.org
References
- http://osvdb.org/36579
- http://secunia.com/advisories/26333Vendor Advisory
- http://sourceforge.net/forum/forum.php?forum_id=722865
- http://sourceforge.net/project/shownotes.php?release_id=530698&group_id=107851
- http://support.ktdms.com/browse/KTS-2178
- http://www.securityfocus.com/bid/25231
- http://www.vupen.com/english/advisories/2007/2812
- http://osvdb.org/36579
- http://secunia.com/advisories/26333Vendor Advisory
- http://sourceforge.net/forum/forum.php?forum_id=722865
- http://sourceforge.net/project/shownotes.php?release_id=530698&group_id=107851
- http://support.ktdms.com/browse/KTS-2178
- http://www.securityfocus.com/bid/25231
- http://www.vupen.com/english/advisories/2007/2812
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.