CVE-2012-10005 is a problematic cross-site scripting (XSS) vulnerability affecting the Textarea Handler component (specifically PFBC/Element/Textarea.php) within the manikandan170890 php-form-builder-class project. An attacker can remotely inject malicious scripts by manipulating the 'value' argument. This vulnerability has a CVSS score of 6.1 (Medium), indicating a low attack complexity and partial impact on confidentiality and integrity, requiring user interaction. While the exploit has been publicly disclosed, there is no evidence of active exploitation, nor are there known Metasploit or ExploitDB modules. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2012-11-22CPE matchmatch criteria | cpe:2.3:a:php-form-builder-class_project:php-form-builder-class:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.