CVE-2010-1995

Tomatocms < 2.0.4 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with "Add new article" privileges, to inject arbitrary web script or HTML via the (1) title, (2) subTitle, and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO.

Scores

EPSS 0.0034
EPSS Percentile 56.0%

Classification

CWE
CWE-79
Status published

Affected Products (8)

tomatocms/tomatocms < 2.0.4
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
tomatocms/tomatocms
n/a/n/a

Timeline

Published May 20, 2010
Tracked Since Feb 18, 2026