Back to Database
Status published
Medium
CVE-2010-1453
Cross-site scripting (XSS) vulnerability in the Login form in Piwik...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1453
Credits & Attribution
No credits recorded in the NVD database.
References
More from matomo
View All →CVE-2022-33156
The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3...
Medium
6.1
CVE-2020-29578
The official piwik Docker images before fpm-alpine (Alpine specific) contain...
Critical
9.8
CVE-2019-12215
A full path disclosure vulnerability was discovered in Matomo v3.9.1...
Medium
4.3
CVE-2015-7816
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows...
High
7.5
CVE-2015-7815
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows...
High
7.5
Affected Vendor
matomo
View all reports →Affected Software
matomo, piwik
Vulnerable Versions:
0.1.6, 0.1.7, 0.1.8, 0.1.9, 0.1.10, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.2.7, 0.2.8, 0.2.9, 0.2.10, 0.2.11, 0.2.12, 0.2.13, 0.2.14, 0.2.16, 0.2.17, 0.2.18, 0.2.19, 0.2.20, 0.2.22, 0.2.23, 0.2.24, 0.2.25, 0.2.26, 0.2.27, 0.2.28, 0.2.29, 0.2.30, 0.2.31, 0.2.32, 0.2.33, 0.2.34, 0.4, 0.4.1, 0.4.4, 0.4.5, 0.5, 0.5.1, 0.5.2, 0.5.3, 0.5.4, 0.5.5
Timeline
Official Publish:
May 7th, 2010
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.