VYPR

Zikula

by Ziku

CVEs (1)

  • CVE-2011-3352MedNov 19, 2019
    risk 0.24cvss 4.8epss 0.01

    Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script…