A vulnerability has been discovered in WWWBoard version 2.0A2.1 and earlier. Due to insufficient sanitization of user-supplied forum input, attackers may embed malicious script code or HTML into forum posts. When a malicious post is viewed by another user, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the software.
A vulnerability has been discovered in WWWBoard version 2.0A2.1 and earlier. Due to insufficient sanitization of user-supplied forum input, attackers may embed malicious script code or HTML into forum posts. When a malicious post is viewed by another user, the attacker-supplied code will be interpreted in their web browser in the security context of the site hosting the software.