Lucene search

K
cve[email protected]CVE-2009-2342
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-2342

2022-10-0316:24:06
CWE-79
web.nvd.nist.gov
21
cve-2009-2342
xss
admin.php
content management made easy
cmme

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.5%

Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the username field.

Affected configurations

NVD
Node
hans_oesterholtcmmeRange1.21
OR
hans_oesterholtcmmeMatch1.02
OR
hans_oesterholtcmmeMatch1.03
OR
hans_oesterholtcmmeMatch1.06
OR
hans_oesterholtcmmeMatch1.07
OR
hans_oesterholtcmmeMatch1.08
OR
hans_oesterholtcmmeMatch1.09
OR
hans_oesterholtcmmeMatch1.10
OR
hans_oesterholtcmmeMatch1.11
OR
hans_oesterholtcmmeMatch1.12
OR
hans_oesterholtcmmeMatch1.18
OR
hans_oesterholtcmmeMatch1.19

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.9 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.5%

Related for CVE-2009-2342