
We found results for “”
WS-2017-0141
Good to know:

Date: December 28, 2012
Affected versions of the package are vulnerable to Cross-site Scripting (XSS).
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version m-comscience/yii2-homer-asset - no_fix;sonlabs/php-paypal - no_fix;kunstmaan/translator-bundle - 3.3.1;kunstmaan/translator-bundle - 3.2.1;kunstmaan/translator-bundle - 4.0.1;kunstmaan/translator-bundle - 4.1.1;kunstmaan/translator-bundle - 4.2.1;kunstmaan/translator-bundle - 3.6.1;kunstmaan/translator-bundle - 3.0.1;kunstmaan/translator-bundle - 3.1.1;kunstmaan/translator-bundle - 3.5.1;kunstmaan/translator-bundle - 3.4.1;kunstmaan/translator-bundle - 5.2.1;kunstmaan/translator-bundle - 5.1.1;kunstmaan/translator-bundle - 5.0.1;blackspot/laravel-starter - 2.x-dev;blackspot/laravel-starter - v2.1.6;blackspot/laravel-starter - v2.1.2;kunstmaan/bundles-cms - 3.3.1;kunstmaan/bundles-cms - 3.2.1;kunstmaan/bundles-cms - 4.1.1;kunstmaan/bundles-cms - 4.2.1;kunstmaan/bundles-cms - dev-analysis-m4agPW;kunstmaan/bundles-cms - 5.1.1;kunstmaan/bundles-cms - 5.0.1;kunstmaan/bundles-cms - 3.6.1;kunstmaan/bundles-cms - 3.0.1;kunstmaan/bundles-cms - 3.5.1;kunstmaan/bundles-cms - 3.1.1;kunstmaan/bundles-cms - 3.4.1;darekmeco/platform - 2.0.1;darekmeco/platform - test;darekmeco/platform - no_fix;darekmeco/platform - 1.15.0;darekmeco/platform - 1.0.1;idavoll/translation-module - 3.5.0;idavoll/translation-module - 2.0.0;idavoll/translation-module - 3.5.1;idavoll/translation-module - dev-dependabot/npm_and_yarn/Themes/Adminlte/moment-2.29.2;idavoll/translation-module - 3.6.1;idavoll/translation-module - 1.1.0;idavoll/translation-module - no_fix;idavoll/translation-module - 2.0.1;idavoll/translation-module - 3.0.1;idavoll/translation-module - test;jimmlog/metradmin - 3.6.2.5;jimmlog/metradmin - no_fix;sunnnnn/yii2-admin - no_fix;sunnnnn/yii2-admin - 1.0.0;networking/init-cms-bundle - dev-feature/symfony5;networking/init-cms-bundle - v3.4.1.9;networking/init-cms-bundle - v3.4.9.10;networking/init-cms-bundle - 2.1.x-dev;networking/init-cms-bundle - v3.4.9.14;networking/init-cms-bundle - v3.4.8;networking/init-cms-bundle - v3.4.1.3;networking/init-cms-bundle - v3.4.1.5;networking/init-cms-bundle - v3.4.4.2;networking/init-cms-bundle - v4.4.12;networking/init-cms-bundle - v3.4.4.4;networking/init-cms-bundle - v3.4.0.3;networking/init-cms-bundle - v3.4.9.8;networking/init-cms-bundle - v3.4.1.1;networking/init-cms-bundle - no_fix;networking/init-cms-bundle - v3.4.9.3;networking/init-cms-bundle - v4.4.9;maarsson/translation - dev-dependabot/npm_and_yarn/Themes/Flatly/marked-4.0.10;maarsson/translation - 2.0.1;maarsson/translation - 2.6.0;maarsson/translation - 1.4.1;maarsson/translation - 1.8.0;maarsson/translation - 3.5.0;maarsson/translation - 1.10.0;sonata-project/admin-bundle - dev-release/3.105.3;sonata-project/admin-bundle - dev-flintci-58639;sonata-project/admin-bundle - dev-VincentLanglet-patch-2;sonata-project/admin-bundle - dev-dependabot/npm_and_yarn/moment-2.29.2;sonata-project/admin-bundle - dev-proxyGeneric;sonata-project/admin-bundle - dev-fix/7361;sonata-project/admin-bundle - dev-release/3.105.2;sonata-project/admin-bundle - 4.0.0-alpha-2;sonata-project/admin-bundle - dev-addTypehint;sonata-project/admin-bundle - dev-master-dev-kit;sonata-project/admin-bundle - dev-VincentLanglet-patch-3;sonata-project/admin-bundle - dev-unused;sonata-project/admin-bundle - dev-3.x-dev-kit;sonata-project/admin-bundle - dev-release/3.107.1;sonata-project/admin-bundle - dev-flintci-50541;sonata-project/admin-bundle - dev-flintci-64458;sonata-project/admin-bundle - dev-release/3.107;i9code/laravelmetronic - no_fix;marciocamello/yii2-x-editable - no_fix;vitalets/x-editable - 1.0.0;denisgold/translation-module - no_fix;denisgold/translation-module - 3.0.1;denisgold/translation-module - test;denisgold/translation-module - 2.0.1;vitalets/x-editable-yii - 1.0.0;vitalets/x-editable-yii - no_fix;zxf/xfadmin - 1.0.0;evgenbel/platform - 1.0.1;evgenbel/platform - 2.0.1;evgenbel/platform - test;socialog/admin - no_fix;farram/yii2-editable-widget - 0.1.0;pygon-git/plugin-core - no_fix;pygon-git/plugin-core - 0.0.1;i9code/laravelmetronic3 - no_fix;topazcms/core - no_fix;ddicloud/ddicms - 1.3.0;ddicloud/ddicms - 1.0.6;ddicloud/ddicms - 1.1.9;ddicloud/ddicms - 1.2.2;ddicloud/ddicms - 1.2.5;ddicloud/ddicms - 1.2.8;ddicloud/ddicms - 1.0.8;ddicloud/ddicms - no_fix;capham/translation-module - no_fix;capham/translation-module - 1.1.0;e282486518/yii2admin - no_fix;brooksyang/entrance - dev-master;fem/spof - v1.0.0;fem/spof - v2.0.0;fem/spof - v1.0.0-beta1;jackcnn/eacoophp - no_fix;ZChat - no_fix;diandiyun/ddicms - 1.0.3;diandiyun/ddicms - 1.3.1;diandiyun/ddicms - 1.1.7;arionum/pool - no_fix;Loqu8.X-editable - no_fix;tuhuokeji/diandicms - 1.0.0;tuhuokeji/diandicms - dev-main;tuhuokeji/diandicms - 1.0.3;tuhuokeji/diandicms - 1.0.8;tuhuokeji/diandicms - no_fix;jjsoft-ar/translation-module - no_fix;jjsoft-ar/translation-module - 1.1.0;bitsoflove-asgard/translation - 1.1.0;wz-sistemas/cobranca - no_fix;imaginacms/platform - no_fix;imaginacms/platform - 1.0.0;kmaking/admin-template - v1.0.1;kmaking/admin-template - no_fix;kmaking/admin-template - v1.0.4;coolms/twbs - no_fix;diego3/myframework-core - no_fix;armoni/platform - 1.0.0;armoni/platform - no_fix;eng-mmarouf/metronic - no_fix;appcia/webwork - 0.8;imagina/translation-module - 1.1.0;imagina/translation-module - no_fix;waigeo/jsloggerbundle - 1.0.1;waigeo/jsloggerbundle - 1.0.0;ns/color-admin-bundle - dev-BS4;ns/color-admin-bundle - no_fix;ns/color-admin-bundle - 0.1.0;dbrisinajumi/x-editable-yii - no_fix;dbrisinajumi/x-editable-yii - 1.0.0;asgardcms/translation-module - 1.1.0;asgardcms/translation-module - no_fix;imagina/cms-platform - no_fix;imagina/cms-platform - 1.0.0;Gcms.CoreLibrary - no_fix;wysihtml5 - no_fix;tellaw/sunshine-admin-bundle - v0.9.21;tellaw/sunshine-admin-bundle - v0.9.23;tellaw/sunshine-admin-bundle - v0.9.10;cargic/blog - no_fix;diego3/myframework-skeleton - no_fix;safaricco/admfw - no_fix;techpromux/base-bundle - 1.0;techpromux/base-bundle - no_fix;leonardowang/patient - no_fix;for023/ds - dev-master;fastd/asset-bundle - no_fix;kiyora/dashboard-generator - no_fix;shurupov/qengine - no_fix;twedoo/stone - no_fix;wh/xeditable-bundle - no_fix;lednick-project/admin-bundle - 2.1.0;lednick-project/admin-bundle - 3.1.0;lednick-project/admin-bundle - 2.0.0;wafl/core-controls - no_fix;hexmedia/administrator-bundle - no_fix;brix/admin-bundle - no_fix;strausmann/x-editable - 1.0.0;strausmann/x-editable - no_fix;syscontrollers/admin - v0.0.4;reedboat/yiiwheels - 1.0.0;mauricioschmitz/homer-assets - no_fix;msbios/cpanel - v1.0.20;asgardcms/platform - test;asgardcms/platform - 2.0.1;asgardcms/platform - 1.0.1;asgardcms/platform - 1.0.0;asgardcms/platform - no_fix;asgardcms/platform - 1.15.0;asgardcms/platform - 2.0.0;2amigos/yiiwheels - 1.0.7-beta;2amigos/yiiwheels - 2.0.0;2amigos/yiiwheels - 1.0.0;aryaduta/metronic-bundle - no_fix;fedorov-aleksey/yii2-package-theme-absolute-admin - v1.0.2;fedorov-aleksey/yii2-package-theme-absolute-admin - no_fix;cobase/cobase - no_fix;kingkernel/marrento - stable;kingkernel/marrento - no_fix;perminder-klair/yii2-x-editable - no_fix;maioradv/admin2-cdn - no_fix;i9code/metronic - no_fix;yinhe/yincart - no_fix;ristorantino/plugins - dev-master;cigarrita-worker/cigarrita-api - no_fix;crisu83/yiistrap-widgets - 1.0.0;crisu83/yiistrap-widgets - no_fix;khaled3afan/linkati - no_fix;laradium/laradium - dev-feature/belongsto-refactor;laradium/laradium - dev-htmlpreview;x-editable - 1.5.3;jjsoft-ar/platform - no_fix;jjsoft-ar/platform - 1.0.0;g2design/g2-modules - no_fix;hustshenl/yii2-metronic - no_fix;tonetlds/alfredapp - no_fix;msbios/dashboard - no_fix;dukeann/laradmin - 1.0;fpmsdis/sdisauth - no_fix;woldy/cms - no_fix;madephp/framework - no_fix;hakoncms/hakoncms - no_fix;amintado/yii2-aprico-asset - no_fix;wayfirer/ddicms - no_fix;twedoo/volcator - no_fix;rmzamora/admin-bundle - no_fix;awcode/cloudmngr - no_fix;igeekspace/twothink - no_fix;diginova/yii2-metronic - no_fix;diginova/yii2-metronic - 0.1RC;WebProject - no_fix;2amigos/yii2-editable-widget - no_fix;tuananh-web/asset-management - no_fix;kotchuprik/yii2-x-editable - no_fix;jimmlog/modern - v1.9.0;zikwall/simple-mvc - no_fix;imagina/itranslation-module - 3.0.1;bktz/cup - no_fix;guoyu/yii2admin - no_fix;abbassi/infographics - dev-master;vwlabs/vwtranslation-module - no_fix;qla/adminpanel - no_fix;smartysoft/yii2-smartysoft-ample - no_fix;sagsoz06/translation-module - 2.1.4;notegame/asgardcms - 1.0.0;nonameffh/yii2-x-editable - no_fix;procoders/admin - 1.0.0;laraflat/laraflat - no_fix;odwini/asgardcms-translation - no_fix;alternatex/store - no_fix;sagsoz06/adminlte-theme - no_fix;skeeks/yii2-template-smarty - 1.0.0;petrkoznar/x-editable - no_fix;tecnodesignc/translation-module - no_fix;sentora/laravel-base-sentora - no_fix;bardis/cms-symfony2 - 2.8.8;IIKI.BaseApp.Web - no_fix;symfomany/laravelcinema - no_fix;Server2 - no_fix;fadriqueclickennet/translation-module - no_fix;doitonlinemedia/admin - no_fix;i9code/laravelmetronic2 - no_fix;luokuncool/easy-workflow - no_fix;raalveco/scaffolding - no_fix;pine207/pine-dashboard - no_fix;org.webjars.npm:x-editable-bs5:no_fix;org.webjars.npm:x-editable-bs4:no_fix;org.webjars.npm:github-com-skycyclone-x-editable:no_fix;org.webjars.npm:x-editable:no_fix;org.webjars.npm:x-editable-4-bs4:no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |