Cross-site Scripting in Elgg Prior to 1.8.5
CVE-2012-6561

Currently unrated

Key Information:

Vendor

Elgg

Status
Vendor
CVE Published:
23 May 2013

What is CVE-2012-6561?

An XSS vulnerability exists in the Elgg platform in the engine/lib/views.php file, affecting versions before 1.8.5. This vulnerability allows attackers to inject arbitrary web scripts or HTML through the view parameter in index.php, potentially leading to the execution of malicious scripts in user browsers. This can compromise user data, session cookies, or any sensitive information stored in the browser.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.