It has been reported that BoastMachine may be prone to an HTML injection vulnerability that may allow a remote attacker to execute HTML and script code in a user's browser. The problem is reported to exist due to improper sanitizing of user-supplied data in the 'Comment' form. This vulnerability has been reported to exist in BoastMachine version 2.6, however it is possible that other versions are affected as well.
It has been reported that BoastMachine may be prone to an HTML injection vulnerability that may allow a remote attacker to execute HTML and script code in a user's browser. The problem is reported to exist due to improper sanitizing of user-supplied data in the 'Comment' form. This vulnerability has been reported to exist in BoastMachine version 2.6, however it is possible that other versions are affected as well.