vendor:
PForum
by:
7.5
CVSS
HIGH
HTML Injection
79
CWE
Product Name: PForum
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
PScript PForum HTML Injection Vulnerability
The PScript PForum is vulnerable to an HTML injection attack due to insufficient sanitization of user input in the user profile form. This vulnerability can be exploited to steal cookie-based authentication credentials and potentially exploit browser security flaws.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input sanitization and validation techniques to prevent the injection of malicious HTML code. Additionally, users should be cautious when clicking on untrusted links or visiting untrusted websites.