Show plain JSON{"id": "CVE-2012-4234", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}]}, "published": "2014-09-04T14:55:09.600", "references": [{"url": "http://archives.neohapsis.com/archives/bugtraq/2012-08/0189.html", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.org/files/116057/Phorum-5.2.18-Cross-Site-Scripting.html", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://secunia.com/advisories/50445", "source": "cve@mitre.org"}, {"url": "http://www.phorum.org/phorum5/read.php?64%2C151943", "source": "cve@mitre.org"}, {"url": "http://www.securityfocus.com/bid/55275", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78124", "source": "cve@mitre.org"}, {"url": "https://www.htbridge.com/advisory/HTB23109", "tags": ["Exploit"], "source": "cve@mitre.org"}, {"url": "http://archives.neohapsis.com/archives/bugtraq/2012-08/0189.html", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://packetstormsecurity.org/files/116057/Phorum-5.2.18-Cross-Site-Scripting.html", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/50445", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.phorum.org/phorum5/read.php?64%2C151943", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/55275", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78124", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.htbridge.com/advisory/HTB23109", "tags": ["Exploit"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter."}, {"lang": "es", "value": "Vulnerabilidad de XSS en la pantalla de la moderaci\u00f3n de grupos en el centro de control (control.php) en Phorum anterior a 5.2.19 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a trav\u00e9s del par\u00e1metro group."}], "lastModified": "2025-04-12T10:46:40.837", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:phorum:phorum:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7658DEE-525F-4A02-9577-4830FFE9CB1F", "versionEndIncluding": "5.2.18"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4C4E79D-EBE6-456C-A74F-B94F32736383"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3596808-8399-4EA9-B885-5443CA91C3C3"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90FC064F-B462-47F8-880F-CB26A340477E"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.10:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D083445E-48ED-4666-98A8-932B01A0F9B2"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A79911F1-C1C3-4DD1-BA37-AFC77D7B0D90"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2200E549-30F8-4803-A570-FBF08B97B7CD"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.12:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A94B0DAF-C8AC-483F-A280-CCF4B6D17BF0"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9876C40-4537-4622-90D5-175AB59609D4"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "51638139-DB4F-4B8C-B125-1FE9AFC86B21"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6362BDF1-A90C-40A8-A80C-024788426315"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.15:a:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "211355E8-5707-4873-AE47-26DFE6061725"}, {"criteria": "cpe:2.3:a:phorum:phorum:5.2.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "61C297BC-DF74-42FD-957B-6130AEAA3A04"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}