CVE-2012-1209
Fork-cms Fork Cms < 3.2.5 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.6%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
fork-cms/fork_cms
forkcms/forkcms
< 3.2.5Packagist
n/a/n/a
Timeline
Published
Feb 24, 2012
Tracked Since
Feb 18, 2026