Multiple Cross-Site Scripting Vulnerabilities in Saurus CMS by Saurus
CVE-2015-1562

Currently unrated

Key Information:

Vendor

Saurus

Vendor
CVE Published:
9 February 2015

What is CVE-2015-1562?

Multiple cross-site scripting (XSS) vulnerabilities exist in Saurus CMS 4.7.0 that enable remote attackers to inject arbitrary web scripts or HTML. These vulnerabilities can be exploited through the search parameter in admin/user_management.php, the data_search parameter in admin/profile_data.php, and the filter parameter in error_log.php. Successful exploitation of these vulnerabilities can compromise user data and application integrity by enabling attackers to execute malicious scripts in the context of the user’s session or browser.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.