PT-2004-3406 · Powerportal · Powerportal

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2514

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PowerPortal versions 1.x
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the SUBJECT or MESSAGE field in the private messages module.
Recommendations For PowerPortal version 1.x, update the private messages module to prevent injection of arbitrary web script or HTML via the SUBJECT or MESSAGE field.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2514

Affected Products

Powerportal