vendor:
BoardPower Forum
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: BoardPower Forum
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-Unknown
CPE: a:boardpower_forum
Platforms Tested: Unknown
Unknown
Cross-Site Scripting Vulnerability in BoardPower Forum
A remote attacker can create a malicious link to the vulnerable application that includes hostile HTML and script code. If the link is followed, the hostile code may be rendered in the web browser of the victim user, potentially allowing for theft of cookie-based authentication credentials or other attacks.
Mitigation:
Proper input sanitization and validation should be implemented to prevent cross-site scripting vulnerabilities.