MiniBB Profile Website Name HTML...

- AV AC AU C I A
发布: 2003-12-29
修订: 2025-04-13

miniBB is prone to an HTML injection vulnerability. This issue could permit registered users to inject hostile HTML and script code into the 'website name' field of their user profile, which would be rendered by other web users when the user profile is viewed. This could be exploited to steal cookie-based authentication credentials. It is also possible to use this type of vulnerability as an attack vector to exploit latent browser security flaws.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息