Description
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Published: 2022-06-30
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-11129 A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
History

No history.

Subscriptions

Bitrix24 Bitrix Site Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-04-15T14:08:44.945Z

Reserved: 2022-06-27T00:00:00.000Z

Link: CVE-2017-20122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-30T05:15:07.067

Modified: 2024-11-21T03:22:41.507

Link: CVE-2017-20122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses