PT-2018-12811 · My Little Forum · My Little Forum

Published

2018-08-05

·

Updated

2024-02-14

·

CVE-2018-14936

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions my little forum version 2.4.12
Description The issue allows for XSS via the Title field in the Add page option.
Recommendations For my little forum version 2.4.12, update to a version that fixes this issue, if available. As a temporary workaround, consider validating and sanitizing user input in the Title field to prevent XSS attacks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-14936

Affected Products

My Little Forum