{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML, (5) FirstParagraph, (6) FirstSentence, (7) Initial, (8) LimitCharacters, (9) LimitSentences, (10) LimitWordCount, (11) LimitWordCountXML, (12) Lower, (13) LowerCase, (14) NoHTML, (15) Summary, (16) Upper, (17) UpperCase, or (18) URL method in a template, different vectors than CVE-2012-0976."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-09-17T17:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7"},{"name":"[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/04/30/1"},{"name":"[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/04/30/3"},{"tags":["x_refsource_CONFIRM"],"url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/silverstripe/sapphire/commit/0085876"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-4968","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe 2.3.x before 2.3.13 and 2.4.x before 2.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted string to the AbsoluteLinks, (2) BigSummary, (3) ContextSummary, (4) EscapeXML, (5) FirstParagraph, (6) FirstSentence, (7) Initial, (8) LimitCharacters, (9) LimitSentences, (10) LimitWordCount, (11) LimitWordCountXML, (12) Lower, (13) LowerCase, (14) NoHTML, (15) Summary, (16) Upper, (17) UpperCase, or (18) URL method in a template, different vectors than CVE-2012-0976."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7","refsource":"CONFIRM","url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7"},{"name":"[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/04/30/1"},{"name":"[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2012/04/30/3"},{"name":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13","refsource":"CONFIRM","url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13"},{"name":"https://github.com/silverstripe/sapphire/commit/0085876","refsource":"CONFIRM","url":"https://github.com/silverstripe/sapphire/commit/0085876"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T20:50:18.409Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.4.7"},{"name":"[oss-security] 20120430 CVE-request: SilverStripe before 2.4.4","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/04/30/1"},{"name":"[oss-security] 20120430 Re: CVE-request: SilverStripe before 2.4.4","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/04/30/3"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://doc.silverstripe.org/framework/en/trunk/changelogs/2.3.13"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/silverstripe/sapphire/commit/0085876"}]}]},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-4968","datePublished":"2012-09-17T17:00:00.000Z","dateReserved":"2012-09-17T00:00:00.000Z","dateUpdated":"2024-09-16T19:11:05.166Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}