Collabtive · Collabtive · CVE-2019-8935
**Name of the Vulnerable Software and Affected Versions**
Collabtive version 3.1
**Description**
The issue allows for XSS via the `manageuser.php?action=profile` API endpoint, specifically through the `id` parameter.
**Recommendations**
For Collabtive version 3.1, avoid using the `id` parameter in the `manageuser.php?action=profile` API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.