vendor:
Codoforum
by:
Vyshnav Vizz
8.8
CVSS
HIGH
Persistent Cross-site Scripting
79
CWE
Product Name: Codoforum
Affected Version From: 4.8.3
Affected Version To: 4.8.3
Patch Exists: NO
Related CWE: N/A
CPE: a:codoforum:codoforum:4.8.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
Codoforum 4.8.3 – Persistent Cross-Site Scripting
Codoforum is prone to a Persistent Cross-site Scripting Vulnerability in User-Comment replay section. An attacker can exploit this issue to creating user with payload and perform cross-site scripting attacks. Codoforum version 4.8.3 is vulnerable.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.