CVE-2012-1296

Elefantcms < 1.1.4_beta - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in apps/admin/handlers/preview.php in Elefant CMS 1.0.x before 1.0.2-Beta and 1.1.x before 1.1.5-Beta allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body parameter to admin/preview.

Scores

EPSS 0.0052
EPSS Percentile 66.4%

Classification

CWE
CWE-79
Status published

Affected Products (6)

elefantcms/elefantcms < 1.1.4_beta
elefantcms/elefantcms
elefantcms/elefantcms
elefantcms/elefantcms
elefant/cms < 1.0.2-BetaPackagist
n/a/n/a

Timeline

Published Aug 26, 2012
Tracked Since Feb 18, 2026