XenForo 1.4.9 Cross Site Scripting

2015.07.28
Credit: WRZ
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

[+] Credits: snop. [+] Domains: rabbitz.org Vulnerability Type: =================== XSS Vendor: =================== www.xenforo.com Product: ===================================================================== XenForo <= 1.4.9 A compelling community experience. Intuitive. Social. Engaging. Fast. XenForo brings a fresh outlook to forum software. Advisory Information: ==================================================== Reflected Cross Site Scripting Vulnerability: Vulnerability Details: ===================== No Useraccount required. ------------------------------------ vulnerable URL: https://website/community/register/validate-field vulnerable POST parameter: 'name=' Severity Level: ========================================================= High


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top