Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter.
CPE | Name | Operator | Version |
---|---|---|---|
bigtree_cms | eq | 4.0 b1 | |
bigtree_cms | eq | 4.0 b7 | |
bigtree_cms | eq | 4.0 b5 | |
bigtree_cms | eq | 4.0 b6 | |
bigtree_cms | le | 4.0 | |
bigtree_cms | eq | 4.0 rc1 | |
bigtree_cms | eq | 4.0 b3 | |
bigtree_cms | eq | 4.0 b2 | |
bigtree_cms | eq | 4.0 b4 |