PT-2021-11448 · Unknown · Online Discussion Forum
J5Oh
·
Published
2021-04-19
·
Updated
2021-04-23
·
CVE-2020-28141
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Online Discussion Forum version 1.0
Description:
The messaging subsystem is susceptible to a cross-site scripting (XSS) issue in the message body, allowing an authenticated user to send messages containing javascript code that executes when the recipient views the messages page.
Recommendations:
For Online Discussion Forum version 1.0, consider disabling the messaging subsystem until a patch is available to prevent potential XSS attacks. Restrict access to the message body feature to minimize the risk of exploitation. Avoid allowing users to include javascript code in messages until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Discussion Forum