VulnerabilityModified
CVE-2009-4822
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.
MEDIUM 4.3EPSS 1.46%
Does this matter?
Lower severity and a low EPSS score (1.46%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) do, (2) id, and (3) uname parameters.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.46% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- kasseler-cms/kasseler cms
- Source
- cve@mitre.org
References
- http://www.exploit-db.com/exploits/10581Exploit
- http://www.securityfocus.com/bid/37435Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54953
- http://www.exploit-db.com/exploits/10581Exploit
- http://www.securityfocus.com/bid/37435Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54953
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.