PT-2021-11448 · Unknown · Online Discussion Forum

J5Oh

·

Published

2021-04-19

·

Updated

2021-04-23

·

CVE-2020-28141

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Online Discussion Forum version 1.0
Description: The messaging subsystem is susceptible to a cross-site scripting (XSS) issue in the message body, allowing an authenticated user to send messages containing javascript code that executes when the recipient views the messages page.
Recommendations: For Online Discussion Forum version 1.0, consider disabling the messaging subsystem until a patch is available to prevent potential XSS attacks. Restrict access to the message body feature to minimize the risk of exploitation. Avoid allowing users to include javascript code in messages until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28141

Affected Products

Online Discussion Forum