First published: Tue Dec 31 2002(Updated: )
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Working Resources Inc. BadBlue | =personal_1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1683 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
CVE-2002-1683 allows attackers to inject arbitrary scripts into the cleanSearchString() function, affecting other users of BadBlue Personal Edition 1.7.3.
To fix CVE-2002-1683, upgrade to a version of BadBlue Personal Edition that does not contain this vulnerability.
Users of BadBlue Personal Edition version 1.7.3 are impacted by CVE-2002-1683.
CVE-2002-1683 is a cross-site scripting (XSS) vulnerability.