Jojo CMS 'search' Parameter Cross-Site Scripting Vulnerability
Release date:
Updated on:
Affected Systems:
Jojo CMS <1.2.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 59933
CVE (CAN) ID: CVE-2013-3082
Jojo CMS is SEO-friendly, scalable, and PHP-based CMS.
In versions earlier than Jojo CMS 1.2.2, plugins/jojo_core/forgot_password.php has the XSS vulnerability. Remote attackers can inject arbitrary Web scripts or HTML by sending search parameters to forgot-password.
<* Source: High-Tech Bridge SA (http://www.htbridge.ch /)
Link: http://xforce.iss.net/xforce/xfdb/84286
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Jojo CMS
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://github.com/JojoCMS/Jojo-CMS
This article permanently updates the link address: