MEDIUM
Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570
Published Jan 28, 2011
4.3
MEDIUMCVSS 2.0
EPSS 2.23%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.