3.5
CVSSv2

CVE-2012-5388

Published: 24/10/2012 Updated: 29/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in wlcms-plugin.php in the White Label CMS plugin 1.5 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, a related issue to CVE-2012-5387.

Vulnerable Product Search on Vulmon Subscribe to Product

videousermanuals white-label-cms 1.5

Exploits

# Exploit Title: White Label CMS v 15 CSRF w/ persistent XSS # Date: 21/10/2012 # Exploit Author: pcsjj # Vendor Homepage: wwwvideousermanualscom/white-label-cms/ # Version: 15 # Software Link: pluginssvnwordpressorg/white-label-cms/branches/ # Downloads: 110,313 # CVE : CVE-2012-5387 (CSRF), CVE-2012-5388 (XSS) <html> & ...
White Label CMS version 15 suffers from cross site request forgery and cross site scripting vulnerabilities ...