Reflected XSS Vulnerability in Discuz! Forum Software by Discuz
CVE-2018-10298

5.4MEDIUM

Key Information:

Vendor

Discuz

Status
Vendor
CVE Published:
22 April 2018

What is CVE-2018-10298?

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Discuz! forum software, specifically in DiscuzX version X3.4. When users attempt to create a new thread via the forum, the application fails to properly sanitize input within the 'forum.php?mod=post&action=newthread' endpoint. Consequently, untrusted data can be reflected back to users, allowing attackers to inject malicious scripts into unsuspecting users’ browsers. This exploitation can lead to unauthorized access, data theft, and further attacks on users interacting with compromised content.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.