PT-2003-1195 · L Forum · L-Forum

Published

2003-03-18

·

Updated

2008-09-05

·

CVE-2002-1458

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions L-Forum versions 2.40 and earlier
Description A cross-site scripting issue exists when the "Enable HTML in messages" option is enabled, allowing remote attackers to insert arbitrary script or HTML via message fields including From, E-Mail, Subject, and Body.
Recommendations For L-Forum versions 2.40 and earlier, disable the "Enable HTML in messages" option to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1458

Affected Products

L-Forum