PT-2023-11351 · Unknown · Dragonexpert
Published
2023-01-02
·
Updated
2024-05-17
·
CVE-2019-25093
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
dragonexpert Recent Threads on Index (affected versions not specified)
Description
A problematic vulnerability was found in the function
recentthread list threads of the file inc/plugins/recentthreads/hooks.php of the component Setting Handler. The manipulation of the argument recentthread forumskip leads to cross-site scripting. It is possible to launch the attack remotely.Recommendations
To fix this issue, it is recommended to apply a patch. Specifically, the patch identified as
051465d807a8fcc6a8b0f4bcbb19299672399f48 should be applied. As a temporary workaround, consider disabling the recentthread list threads function until the patch is applied. Additionally, restrict access to the inc/plugins/recentthreads/hooks.php file to minimize the risk of exploitation. Avoid using the argument recentthread forumskip in the affected component until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dragonexpert