Posted by Steffen Rösemann on Dec 24
Advisory: Reflecting XSS Vulnerability in CMS Contenido 4.9.x-4.9.5
Advisory ID: SROEADV-2014-03
Author: Steffen Rösemann
Affected Software: CMS Contenido 4.9.x-4.9.5 (Release: 10th Dec 2014)
Vendor URL: http://www.contenido.org/de/
Vendor Status: fixed
CVE-ID: –
==========================
Vulnerability Description:
==========================
The Content Management System Contenido 4.9.x to 4.9.5 has a reflecting XSS
vulnerability in its…