CVE-2012-6513
gpEasy CMS 2.3.3 - Cross-Site Scripting via jsoncallback Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-6513. PoCs published by Jakub Galczyk.
AI-analyzed exploit summary This exploit demonstrates a cross-site scripting (XSS) vulnerability in gpEasy by injecting arbitrary script code via the 'jsoncallback' parameter in the Admin_Preferences endpoint. The vulnerability arises due to insufficient input sanitization.
Description
Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or HTML via the jsoncallback parameter.
Exploits (1)
This exploit demonstrates a cross-site scripting (XSS) vulnerability in gpEasy by injecting arbitrary script code via the 'jsoncallback' parameter in the Admin_Preferences endpoint. The vulnerability arises due to insufficient input sanitization.