Multiple cross-site scripting (XSS) vulnerabilities in Caravel CMS 3.0 Beta 1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fileDN and (2) folderviewer_attrs parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Caravel_cms | Caravel_cms | * | 3.0_beta_1 (including) |