Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editerauteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the urlsite parameter.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.0.14-1", "binary_name": "spip" } ] }