Leszek Krupinski L-Forum Message...

- AV AC AU C I A
发布: 2002-08-14
修订: 2025-04-13

A script injection vulnerability has been reported in L-Forum 2.4.0. Malicious messages may be posted to the forum which include arbitrary HTML content, including JavaScript code. If the message is then viewed by another user of the system, the supplied script code will execute within the context of the vulnerable site. This flaw is due to insufficient filtering of the 'From', 'E-mail' and 'Subject' fields of a message post.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息