CVE-2012-4950
Status: ModifiedMedium (4.3)—
Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.33%
- Percentile among all scored CVEs: 70
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
- http://osvdb.org/87053
- http://secunia.com/advisories/51203
- http://www.kb.cert.org/vuls/id/802596
- http://www.securityfocus.com/bid/56381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79787
- http://osvdb.org/87053
- http://secunia.com/advisories/51203
- http://www.kb.cert.org/vuls/id/802596
- http://www.securityfocus.com/bid/56381
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79787
Raw JSON (NVD)
Show
{
"id": "CVE-2012-4950",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-11-18T21:55:01.197",
"references": [
{
"url": "http://osvdb.org/87053",
"source": "cret@cert.org"
},
{
"url": "http://secunia.com/advisories/51203",
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/802596",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/56381",
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79787",
"source": "cret@cert.org"
},
{
"url": "http://osvdb.org/87053",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/51203",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/802596",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/56381",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/79787",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via crafted characters that are not properly handled during construction of error messages."
},
{
"lang": "es",
"value": "Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en la página de búsqueda de palabras clave en la interfaz web de Pattern Insight v2.3, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de caracteres modificados que no se gestionan correctamente durante la construcción de los mensajes de error."
}
],
"lastModified": "2026-06-16T23:45:57.417",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:patterninsight:pattern_insight:2.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5193A710-0AEB-48F6-A49B-78F91A433ACA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}