CVE-2011-2201
EPSS 6.9%
Description
The Data::FormValidator module 4.66 and earlier for Perl, when untaint_all_constraints is enabled, does not properly preserve the taint attribute of data, which might allow remote attackers to bypass the taint protection mechanism via form input.
How to fix CVE-2011-2201
To remediate CVE-2011-2201, upgrade the affected package to a fixed version below.
- Debian/libdata-formvalidator-perl—upgrade to 4.66-3 or later
Is CVE-2011-2201 being exploited?
Moderate — EPSS is 6.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 4.66-3