CVE-2012-4543

Severity
4.3MEDIUM
EPSS
0.2%
top 53.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 4
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3rg2-g53j-xh7w: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 82022-05-17
CVEList
CVE-2012-4543: Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 82013-01-04

📋Vendor Advisories

1
Red Hat
System: Multiple cross-site scripting flaws by displaying CRL or processing profile2012-12-06

💬Community

3
Bugzilla
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [fedora-all]2012-12-06
Bugzilla
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile [epel-5]2012-12-06
Bugzilla
CVE-2012-4543 Certificate System: Multiple cross-site scripting flaws by displaying CRL or processing profile2012-10-09
CVE-2012-4543 (MEDIUM CVSS 4.3) | Multiple cross-site scripting (XSS) | cvebase.io