PT-2003-1195 · L Forum · L-Forum
Published
2003-03-18
·
Updated
2008-09-05
·
CVE-2002-1458
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
L-Forum versions 2.40 and earlier
Description
A cross-site scripting issue exists when the "Enable HTML in messages" option is enabled, allowing remote attackers to insert arbitrary script or HTML via message fields including
From, E-Mail, Subject, and Body.Recommendations
For L-Forum versions 2.40 and earlier, disable the "Enable HTML in messages" option to prevent exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
L-Forum