Cross-Site Scripting Vulnerability in Acuity CMS by Acuity
CVE-2012-4745

Currently unrated

Key Information:

Vendor
CVE Published:
31 August 2012

What is CVE-2012-4745?

A cross-site scripting (XSS) vulnerability exists in the login page (admin/login.asp) of Acuity CMS version 2.6.2. This vulnerability enables remote attackers to inject arbitrary HTML or web script code through the UserName parameter, potentially compromising the security and integrity of user sessions. By exploiting this flaw, malicious actors can execute harmful scripts in the context of the user's session, leading to data theft or further attacks within the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.