CVE-2012-5650

Description

Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.895

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2010-3854,CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.0.0Windows
Vulnerabilities CVE-2010-3854,CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.0.1Windows
Vulnerabilities CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.0.2Windows
Vulnerabilities CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.0.3Windows
Vulnerabilities CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.1.0Windows
Vulnerabilities CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.1.1Windows
Vulnerabilities CVE-2012-5641,CVE-2012-5649,CVE-2012-5650 are affected in Apache CouchDB 1.2.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234