vendor:
XOOPS
by:
High-Tech Bridge SA Security Research Lab
4,3
CVSS
MEDIUM
XSS (Cross Site Scripting)
79
CWE
Product Name: XOOPS
Affected Version From: 2.5.4
Affected Version To: 2.5.4
Patch Exists: YES
Related CWE: CVE-2012-0984
CPE: a:xoops:xoops
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012
Multiple Cross-Site Scripting (XSS) in XOOPS
Input passed via the 'to_userid' POST parameter to /modules/pm/pmlite.php and 'current_file' POST parameter to /class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php is not properly sanitised before being returned to the user, which can be exploited to execute arbitrary HTML and script code in a user's browser session in context of affected website.
Mitigation:
Upgrade to the latest version of XOOPS