Description
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Reusable Blocks Extended Cross-Site Request Forgery (0.9)
WordPress Plugin ApplyOnline-Application Form Builder and Manager Arbitrary File Disclosure (1.9.92)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-0499)
WordPress Plugin Timetable and Event Schedule by MotoPress Cross-Site Request Forgery (2.4.1)