VULNERABILITY INTELLIGENCE
CVE-2012-2235
CVSS score4.3 NONE
EPSS probability0.95%
CISA KEVNot currently listed
Published2012-05-27
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Description
Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to index.php, which is not properly handled in an error message.
Weakness classification
- nvd@nist.gov: CWE-79
Primary references
- cve@mitre.org — Exploit
- af854a3a-2127-422b-91ae-364da2661108 — Exploit