PT-2023-11351 · Unknown · Dragonexpert

Published

2023-01-02

·

Updated

2024-05-17

·

CVE-2019-25093

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions dragonexpert Recent Threads on Index (affected versions not specified)
Description A problematic vulnerability was found in the function recentthread list threads of the file inc/plugins/recentthreads/hooks.php of the component Setting Handler. The manipulation of the argument recentthread forumskip leads to cross-site scripting. It is possible to launch the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch. Specifically, the patch identified as 051465d807a8fcc6a8b0f4bcbb19299672399f48 should be applied. As a temporary workaround, consider disabling the recentthread list threads function until the patch is applied. Additionally, restrict access to the inc/plugins/recentthreads/hooks.php file to minimize the risk of exploitation. Avoid using the argument recentthread forumskip in the affected component until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25093

Affected Products

Dragonexpert