CVE-2012-1027: Project-Open ]project-Open[
Medium severity, CVSS 4.3. EPSS: 2.3% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.
Affected products
- Project-Open ]project-Open[: version 3.4.0 only; version 3.5.0.1-2 only
Published 2012-02-08. Last modified 2026-06-16.