Unrated severityNVD Advisory· Published Nov 19, 2019· Updated Aug 6, 2024
CVE-2011-3352
CVE-2011-3352
Description
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- access.redhat.com/security/cve/cve-2011-3352mitrex_refsource_MISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
- www.immuniweb.com/advisory/HTB23039mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.