CVE-2012-1932
Description
A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to admin/setting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Wolf CMS 0.75 and earlier has a persistent XSS vulnerability via the setting[admin_email] parameter, allowing remote attackers to inject arbitrary script.
Vulnerability
Wolf CMS versions 0.75 and earlier are susceptible to a persistent cross-site scripting (XSS) vulnerability in the admin settings page. An attacker can inject arbitrary web script or HTML through the setting[admin_email] parameter to the /admin/setting endpoint [1]. The injected code is stored and executed when an administrator visits the settings page.
Exploitation
An attacker must have access to the admin settings page, which typically requires administrative credentials. However, the vulnerability could be exploited by a malicious admin or via cross-site request forgery (CSRF) if an authenticated admin is tricked into submitting a crafted request. The attacker sends a specially crafted HTTP request with malicious JavaScript in the setting[admin_email] parameter.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the affected admin interface. This can lead to session hijacking, defacement, theft of sensitive information, or further compromise of the Wolf CMS installation.
Mitigation
The official Wolf CMS project may have addressed this issue in versions after 0.75. Users should upgrade to the latest available version. If upgrading is not possible, input validation and output encoding of the admin_email parameter should be implemented. No specific advisory or patch was found in the available reference [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Wolf CMS/Wolf CMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.