Описание
XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.
EPSS
Процентиль: 27%
0.00096
Низкий
Дефекты
CWE-79
Связанные уязвимости
github
около 2 месяцев назад
XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.
EPSS
Процентиль: 27%
0.00096
Низкий
Дефекты
CWE-79