4.3
CVSSv2

CVE-2012-4901

Published: 20/05/2015 Updated: 05/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

template cms project template cms

Exploits

Advisory ID: HTB23115 Product: Template CMS Vendor: template-cmsru Vulnerable Version(s): 211 and probably prior Tested Version: 211 Vendor Notification: September 12, 2012 Public Disclosure: October 3, 2012 Vulnerability Type: Cross-Site Scripting [CWE-79], Cross-Site Request Forgery [CWE-352] CVE References: CVE-2012-4901, CVE-2012-4902 CV ...
Template CMS version 211 suffers from cross site request forgery and cross site scripting vulnerabilities ...