Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the nb parameter (aka the page limit number).
| Software | From | Fixed in |
|---|---|---|
| dotclear / dotclear | 2.12.1 | 2.12.1.x |