CVE-2012-1208
Fork-cms Fork Cms - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) report parameter to blog/settings or (2) error parameter to users/index.
Exploits (2)
References (7)
Scores
EPSS
0.0624
EPSS Percentile
90.8%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
fork-cms/fork_cms
n/a/n/a
Timeline
Published
Feb 24, 2012
Tracked Since
Feb 18, 2026