Description
Multiple cross-site scripting (XSS) vulnerabilities in Saurus CMS 4.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to admin/user_management.php, (2) data_search parameter to /admin/profile_data.php, or (3) filter parameter to error_log.php.
References (5)
Core 5
Core References
Exploit x_refsource_misc
http://sroesemann.blogspot.de/2015/01/report-for-advisory-sroeadv-2015-05.html
Various Sources x_refsource_misc
http://sroesemann.blogspot.de/2015/01/sroeadv-2015-05.html
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jan/112
Exploit mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/01/28/8
Scores
EPSS
0.0040
EPSS Percentile
60.8%
Details
CWE
CWE-79
Status
published
Products (1)
saurus/saurus_cms
4.7.0
Published
Feb 09, 2015
Tracked Since
Feb 18, 2026