CVE-2011-3687
Sonexis ConferenceManager 9.2.11.0 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Sonexis ConferenceManager 9.2.11.0 allow remote attackers to inject arbitrary web script or HTML via (1) the txtConferenceID parameter to HostLogin.asp, (2) the txtConferenceID parameter to ParticipantLogin.asp, (3) the acp parameter to ForgotPIN.asp, or the (4) Description, (5) title, or (6) Heading parameter to Error.asp.
Scores
EPSS
0.0032
EPSS Percentile
54.5%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
sonexis/conferencemanager
n/a/n/a
Timeline
Published
Sep 27, 2011
Tracked Since
Feb 18, 2026