Cross-Site Scripting Vulnerabilities in XOOPS from XOOPS Foundation
CVE-2011-4565

Currently unrated

Key Information:

Vendor

Xoops

Status
Vendor
CVE Published:
28 November 2011

What is CVE-2011-4565?

Multiple cross-site scripting vulnerabilities exist in XOOPS version 2.5.1.a and potentially earlier versions. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML. Exploitation can occur via the 'text' parameter in 'include/formdhtmltextarea_preview.php' or through the 'img' BBCODE tag within the 'message' parameter in 'pmlite.php' (Private Message module). This exposes users to significant security risks, as attackers may leverage these vulnerabilities to execute malicious scripts in the context of a user's session.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.