CVE-2011-5042

Gphemsley Sasha - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in inc/lib/lib.base.php in SASHA 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the instructors parameter. NOTE: the original disclosure also mentions the section_title parameter, but this was disputed by the vendor and retracted by the original researcher.

Scores

EPSS 0.0029
EPSS Percentile 51.7%

Classification

CWE
CWE-79
Status published

Affected Products (2)

gphemsley/sasha
n/a/n/a

Timeline

Published Dec 30, 2011
Tracked Since Feb 18, 2026