CVE-2012-2901
Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla!
MEDIUM
Extension Joomla (identification incertaine)
Pertinence : probable
Description
Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php.
Sévérité
4.3
Moyenne · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | MEDIUM | 4.3 (v2.0) |
Produit et versions
- Produit
- Extension Joomla (identification incertaine)
- Corrigée dans
- Non précisée
- Publiée
- 21/05/2012
- Modifiée
- 16/06/2026
- CWE
- CWE-79
Versions concernées
- joomla_content_editor — jusqu'à 2.0.21
- joomla_content_editor — 2.0 – 2.0
Sources
- NVD CVE-2012-2901 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC