vendor:
Simple Machines Forum (SMF)
by:
Unknown
7.5
CVSS
HIGH
HTML Injection
79
CWE
Product Name: Simple Machines Forum (SMF)
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:simplemachines:forum
Platforms Tested: Unknown
Unknown
HTML Injection Vulnerability in Simple Machines Forum (SMF)
The vulnerability allows an attacker to execute arbitrary HTML or script code in a user's browser by injecting malicious content via the font size attribute. This can lead to theft of cookie-based authentication credentials and other potential attacks.
Mitigation:
It is recommended to update to the latest version of Simple Machines Forum (SMF) to prevent this vulnerability. Additionally, input sanitization should be implemented to filter out potentially malicious content.