Back to Database
Status published
Medium
CVE-2012-5911
Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-5911
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/80672
- http://packetstormsecurity.org/files/111294/B2Evolution-CMS-4.1.3-SQL-Injection.html
- http://www.securityfocus.com/bid/52783
- http://vulnerability-lab.com/get_content.php?id=482
- http://b2evolution.net/news/2012/04/06/b2evolution-4-1-4-stable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74458
More from b2evolution
View All →CVE-2022-44036
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload...
Unknown
0
CVE-2022-30935
An authorization bypass in b2evolution allows remote, unauthenticated attackers to...
Unknown
0
CVE-2021-31632
b2evolution CMS v7.2.3 was discovered to contain a SQL injection...
Critical
9.8
CVE-2021-31631
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request...
High
8.8
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows...
High
8.8
Affected Vendor
b2evolution
View all reports →Affected Software
b2evolution
Vulnerable Versions:
4.1.3
Timeline
Official Publish:
November 17th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.