LayerBB 1.1.1 permette XSS tramite i titoli delle conversazioni (PMS). |
https://github.com/AndyRixon/LayerBB/commits/master https://www.exploit-db.com/exploits/46079/ http://packetstormsecurity.com/files/151015/LayerBB-1.1.1-Cross-Site-Scripting.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-17997 |
Vulnerabilità: CVE-2018-17997
