MEDIUM
DaDaBIK 4.3 beta3, when running in a case-sensitive environment, does not include the htmLawed library, which allows remote attackers to bypass the protection mechanism for CVE-2010-4355 and conduct cross-site scripting (XSS) attacks via the (1) html content and (2) rich_editor fields
Published Dec 1, 2010
4.3
MEDIUMCVSS 2.0
EPSS 1.10%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.