Cross-Site Scripting Vulnerability in Acuity CMS by Acuity
CVE-2012-4745
Currently unrated
What is CVE-2012-4745?
A cross-site scripting (XSS) vulnerability exists in the login page (admin/login.asp) of Acuity CMS version 2.6.2. This vulnerability enables remote attackers to inject arbitrary HTML or web script code through the UserName parameter, potentially compromising the security and integrity of user sessions. By exploiting this flaw, malicious actors can execute harmful scripts in the context of the user's session, leading to data theft or further attacks within the application.
