CVE-2011-1401

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-1401
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2011-1401.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2011-1401
Downstream
Related
Published
2011-04-11T18:55:03Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

ikiwiki before 3.20110328 does not ascertain whether the htmlscrubber plugin is enabled during processing of the "meta stylesheet" directive, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences in (1) the default stylesheet or (2) an alternate stylesheet.

References

Affected packages