PT-2013-5299 · Mintboard · Mintboard

Canberk Bolat

·

Published

2013-07-29

·

Updated

2013-07-30

·

CVE-2013-4951

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mintboard version 0.3
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via the name or pass parameters in specific files, including views/login.php and views/signup.php.
Recommendations For Mintboard version 0.3, consider restricting access to the views/login.php and views/signup.php files until a patch is available. As a temporary workaround, avoid using the name and pass parameters in these files to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4951

Affected Products

Mintboard