PT-2006-2961 · Flexbb · Flexbb
Qex
·
Published
2006-04-21
·
Updated
2018-10-18
·
CVE-2006-1977
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FlexBB versions 0.5.7 BETA and earlier
Description
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the
name and message parameters.Recommendations
For FlexBB versions 0.5.7 BETA and earlier, avoid using the
name and message parameters in affected API endpoints until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flexbb