Description
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.
Remediation
References
Related Vulnerabilities
MySQL Resource Management Errors Vulnerability (CVE-2010-3836)
Oracle Database Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1675)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7061)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-5062)