vendor:
FUDforum
by:
Tim Coen of Curesec GmbH
5
CVSS
MEDIUM
XSS, Login CSRF
79,352
CWE
Product Name: FUDforum
Affected Version From: 3.0.6
Affected Version To: 3.0.6
Patch Exists: NO
Related CWE: n/a
CPE: a:fudforum:fudforum:3.0.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2016
Security Advisory – Curesec Research Team
FUDforum is forum software written in PHP. In version 3.0.6, it is vulnerable to multiple persistent XSS issues. This allows an attacker to steal cookies, inject JavaScript keyloggers, or bypass CSRF protection. Additionally, FUDforum is vulnerable to Login-CSRF.
Mitigation:
The vendor has not released a patch for this vulnerability.