CVE-2010-2038
Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php.
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 2.1 LOWAV:N/AC:H/Au:S/C:N/I:P/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gpeasy/gpeasy cms
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/1005-exploits/gpeasycms-xss.txtExploit
- http://secunia.com/advisories/39643Vendor Advisory
- http://www.htbridge.ch/advisory/xss_vulnerability_in_gpeasy_cms.htmlExploit
- http://www.securityfocus.com/archive/1/511388/100/0/threaded
- http://www.securityfocus.com/bid/40330Exploit, Patch
- http://packetstormsecurity.org/1005-exploits/gpeasycms-xss.txtExploit
- http://secunia.com/advisories/39643Vendor Advisory
- http://www.htbridge.ch/advisory/xss_vulnerability_in_gpeasy_cms.htmlExploit
- http://www.securityfocus.com/archive/1/511388/100/0/threaded
- http://www.securityfocus.com/bid/40330Exploit, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.