Persistent XSS Vulnerabilities in JomSocial 1.6.288
JomSocial 1.6.288 is vulnerable to persistent XSS in the status, mobile phone, land phone, state, city, website, college, name, subject and message fields. The XSS can be triggered by entering malicious code in the fields. The XSS is rendered in the tips section of the album listing, admin edit user page, the main jomsocial page in the members avatar field at the top, affected user's profile, who's online, the wall posts, group discussion replies (but not the initial discussion message), people search results, compose message, write message friend list multiselect, new message notification, inbox (main listing), inbox (while reading message), friends approval list, online users mod, latest members mod, latest groups, group listing, group search results, frontend edit group form, admin edit group modal and the report **** admin page.