MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) url, (3) qstr parameter
Published Apr 25, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.85%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.