CVE-2010-1724
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to…
Does this matter?
Lower severity and a low EPSS score (4.10%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.10% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zikula/zikula application framework
- Source
- cve@mitre.org
References
- http://community.zikula.org/index.php?module=News&func=display&sid=3012&title=zikula-1.2.3-release-announcementVendor Advisory
- http://osvdb.org/64096
- http://secunia.com/advisories/39614Vendor Advisory
- http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework.html
- http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework_1.html
- http://www.osvdb.org/64095
- http://www.securityfocus.com/archive/1/510988/100/0/threaded
- http://www.securityfocus.com/bid/39717
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58224
- http://community.zikula.org/index.php?module=News&func=display&sid=3012&title=zikula-1.2.3-release-announcementVendor Advisory
- http://osvdb.org/64096
- http://secunia.com/advisories/39614Vendor Advisory
- http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework.html
- http://www.htbridge.ch/advisory/xss_vulnerability_in_zikula_application_framework_1.html
- http://www.osvdb.org/64095
- http://www.securityfocus.com/archive/1/510988/100/0/threaded
- http://www.securityfocus.com/bid/39717
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58224
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.