Description
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters.
Exploits (1)
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://www.webapp-security.com/wp-content/uploads/2012/03/Wolfcms-0.75-Multiple-Vulnerabilities-CSRF-XSS.txt
Various Sources x_refsource_misc
http://www.webapp-security.com/2012/03/wolfcms/
Scores
EPSS
0.0219
EPSS Percentile
84.6%
Details
CWE
CWE-79
Status
published
Products (1)
ivano_binetti/wolf_cms
< 0.75
Published
Oct 01, 2012
Tracked Since
Feb 18, 2026