CVE-2012-5387
White Label CMS < 1.5.1 - Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, as demonstrated by a developer name containing XSS sequences.
Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en wlcms-plugin.php en el plugin White Label CMS anteriores a v1.5.1 para WordPress, permite a atacantes remotos secuestrar la autenticación de los administradores para peticiones que piden que modifique el nombre del desarrollador a través del parámetro wlcms_o_developer_name en una acción save sobre wp-admin/admin.php, como se demostró por el nombre de desarrollador que contiene secuencias XSS.
White Label CMS version 1.5 suffers from cross site request forgery and cross site scripting vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-10-15 CVE Reserved
- 2012-10-21 CVE Published
- 2012-10-22 First Exploit
- 2024-08-06 CVE Updated
- 2024-11-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://osvdb.org/86568 | Vdb Entry | |
http://packetstormsecurity.org/files/117590/White-Label-CMS-1.5-Cross-Site-Request-Forgery-Cross-Site-Scripting.html | X_refsource_misc | |
http://www.securityfocus.com/bid/56166 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79520 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/22156 | 2012-10-22 | |
http://www.exploit-db.com/exploits/22156 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://wordpress.org/extend/plugins/white-label-cms/changelog | 2017-08-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | <= 1.5 Search vendor "Videousermanuals" for product "White-label-cms" and version " <= 1.5" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.0.2 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.0.2" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.0.3 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.0.3" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.0.4 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.0.4" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.0.5 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.0.5" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.1 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.1" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.2 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.2" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.3 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.3" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.1 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.1" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.2 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.2" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.3 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.3" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.4 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.4" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.5 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.5" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.6 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.6" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|
Videousermanuals Search vendor "Videousermanuals" | White-label-cms Search vendor "Videousermanuals" for product "White-label-cms" | 1.4.7 Search vendor "Videousermanuals" for product "White-label-cms" and version "1.4.7" | - |
Affected
| in | Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | - | - |
Safe
|