VulnerabilityModified
CVE-2012-2901
Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.
MEDIUM 4.3EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- ryan demmer/joomla content editor
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/49206Vendor Advisory
- http://secunia.com/secunia_research/2012-14/Vendor Advisory
- http://www.joomlacontenteditor.net/news/item/jce-21-released?category_id=32
- http://www.securityfocus.com/bid/53559
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75670
- http://secunia.com/advisories/49206Vendor Advisory
- http://secunia.com/secunia_research/2012-14/Vendor Advisory
- http://www.joomlacontenteditor.net/news/item/jce-21-released?category_id=32
- http://www.securityfocus.com/bid/53559
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75670
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.