{"id":"CVE-2012-1209","aliases":[],"url":"https://o3.security/vulnerability/CVE-2012-1209","summary":"Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script…","details":"Cross-site scripting (XSS) vulnerability in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other versions before 3.2.5 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter.","published":"2012-02-24T13:55:07.437","modified":"2026-06-16T23:39:15.343","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[],"fix":{"url":"https://github.com/forkcms/forkcms/commit/c8ec9c58a6b3c46cdd924532c1de99bcda6072ed","label":"forkcms/forkcms@c8ec9c5"},"references":[{"type":"WEB","url":"http://www.fork-cms.com/blog/detail/fork-cms-3-2-5-released"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73393"},{"type":"EXPLOIT","url":"https://github.com/forkcms/forkcms/commit/c8ec9c58a6b3c46cdd924532c1de99bcda6072ed"},{"type":"EXPLOIT","url":"https://github.com/forkcms/forkcms/commit/df75e0797a6540c4d656969a2e7df7689603b2cf"},{"type":"WEB","url":"http://www.fork-cms.com/blog/detail/fork-cms-3-2-5-released"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73393"},{"type":"EXPLOIT","url":"https://github.com/forkcms/forkcms/commit/c8ec9c58a6b3c46cdd924532c1de99bcda6072ed"},{"type":"EXPLOIT","url":"https://github.com/forkcms/forkcms/commit/df75e0797a6540c4d656969a2e7df7689603b2cf"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:39:15.343"}}