VulnerabilityModified
CVE-2012-4950
Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of…
MEDIUM 4.3EPSS 1.33%
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.33% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- patterninsight/pattern insight
- Source
- cret@cert.org
References
- http://osvdb.org/87053
- http://secunia.com/advisories/51203
- http://www.kb.cert.org/vuls/id/802596US Government Resource
- http://www.securityfocus.com/bid/56381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79787
- http://osvdb.org/87053
- http://secunia.com/advisories/51203
- http://www.kb.cert.org/vuls/id/802596US Government Resource
- http://www.securityfocus.com/bid/56381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79787
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.