Cross-Site Scripting (XSS) in newwinform.php in GNUBOARD5 prima 5.3.1.6 consente agli aggressori remoti di inserire lo script Web arbitrario o HTML tramite il parametro titolo popup. |
https://github.com/gnuboard/gnuboard5/blob/b1fc952c7600b825c4b02e2789ddafdea18c8d13/adm/newwinform.php https://github.com/gnuboard/gnuboard5/blob/b1fc952c7600b825c4b02e2789ddafdea18c8d13/adm/newwinformupdate.php https://github.com/gnuboard/gnuboard5/commit/b1fc952c7600b825c4b02e2789ddafdea18c8d13 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15585 |
Vulnerabilità: CVE-2018-15585
