← Back to CVE List

CVE-2011-3352

Published: 2019-11-19T23:15Z
Last Modified: 2024-11-21T01:30Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context of the affected website. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt