Reflected XSS Vulnerability in Discuz! Forum Software by Discuz
CVE-2018-10298
5.4MEDIUM
What is CVE-2018-10298?
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Discuz! forum software, specifically in DiscuzX version X3.4. When users attempt to create a new thread via the forum, the application fails to properly sanitize input within the 'forum.php?mod=post&action=newthread' endpoint. Consequently, untrusted data can be reflected back to users, allowing attackers to inject malicious scripts into unsuspecting users’ browsers. This exploitation can lead to unauthorized access, data theft, and further attacks on users interacting with compromised content.
