{"id":"GHSA-x4x9-4c65-73w8","summary":"Concrete5 Vulnerable to Cross-Site Scripting (XSS)","details":"Cross-site scripting (XSS) vulnerability in concrete5 Japanese 5.5.1 through 5.5.2.1 and concrete5 English 5.5.0 through 5.6.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","aliases":["CVE-2012-5181"],"modified":"2025-04-12T00:42:18.525440Z","published":"2022-05-17T00:22:27Z","database_specific":{"nvd_published_at":"2012-12-21T21:55:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-04-12T00:08:12Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2012-5181"},{"type":"PACKAGE","url":"https://github.com/concretecms/concrete5-legacy"},{"type":"WEB","url":"http://concrete5-japan.org/news/concrete5602ja-release"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN65458431/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2012-000113"}],"affected":[{"package":{"name":"concrete5/concrete5","ecosystem":"Packagist","purl":"pkg:composer/concrete5/concrete5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.5.1"},{"fixed":"5.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x4x9-4c65-73w8/GHSA-x4x9-4c65-73w8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}