CVE-2012-3997

Sayakbanerjee Sticky Notes - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to inject arbitrary web script or HTML via the (1) paste_user or (2) paste_lang parameter to (a) list.php or (b) show.php.

Scores

EPSS 0.0026
EPSS Percentile 48.7%

Classification

CWE
CWE-79
Status published

Affected Products (2)

sayakbanerjee/sticky_notes
n/a/n/a

Timeline

Published Jul 12, 2012
Tracked Since Feb 18, 2026