[Japanese]
|
JVNDB-2012-000113
|
concrete5 vulnerable to cross-site scripting
|
concrete5 contains a cross-site scripting vulnerability.
concrete5 is an open source content management system (CMS). concrete5 contains a cross-site scripting vulnerability.
Yuji Tounai of bogus.jp reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 2.6 (Low) [IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: None
- Availability Impact: None
|
|
Concrete5
- concrete5 Japanese versions 5.5.1 through 5.5.2.1
- concrete5 English versions 5.5.0 through 5.6.0.2
|
|
An arbitrary script may be executed on the user's web browser.
|
[Update the software]
Update to the latest version according to the information provided by the developer.
On December 8, 2012, concrete5 Japanese version 5.6.0.2.ja was released, which addressed this vulnerability.
On February 14, 2013, concrete5 English version 5.6.1 (*) was released, which addressed this vulnerability.
* 5.6.1 Release Notes
http://www.concrete5.org/documentation/background/version_history/5-6-1/
|
Concrete5
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2012-5181
|
- JVN : JVN#65458431
- National Vulnerability Database (NVD) : CVE-2012-5181
|
- [2012/12/21]
Web page was published
[2013/02/20]
Solution was modified
|