Gnuboard · Gnuboard5 · CVE-2018-15583
**Name of the Vulnerable Software and Affected Versions**
GNUBOARD5 versions prior to 5.3.1.6
**Description**
The issue allows remote attackers to inject arbitrary web script or HTML via the `popup title` parameter in the point list.php file. This enables attackers to perform Cross-Site Scripting (XSS) attacks.
**Recommendations**
For versions prior to 5.3.1.6, update to version 5.3.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the point list.php file or disabling the use of the `popup title` parameter until a patch is available.