Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Management feature in the admin component in Chyrp before 2.5.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) user.email or (2) user.website field in a user registration.
References 4 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- jvndb.jvn.jp: JVNDB-2014-000149 third-party-advisoryx_transferred
- http://chyrp.net/2014/11/18/chyrp-251-security-release/ x_transferred
- jvn.jp: JVN#13160869 third-party-advisoryx_transferred
- https://github.com/chyrp/chyrp/commit/43d1b6b266363ae7545d5d49851034eaeec7bebb x_transferred