CVE-2012-6561
Elgg < 1.8.4 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information.
References (5)
Scores
EPSS
0.0040
EPSS Percentile
60.1%
Details
CWE
CWE-79
Status
published
Products (24)
elgg/elgg
< 1.8.4
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
elgg/elgg
... and 14 more
Published
May 23, 2013
Tracked Since
Feb 18, 2026