CVE-2008-5056: XSS
Cross-site scripting (XSS) vulnerability in departmentofflinecontext.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the departmentid parameter to index.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5056?
CVE-2008-5056 is classified as a medium-severity vulnerability due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2008-5056?
To fix CVE-2008-5056, update ActiveCampaign TrioLive to version 1.58.7 or later, which contains the patch for this vulnerability.
Who is affected by CVE-2008-5056?
CVE-2008-5056 affects various versions of ActiveCampaign TrioLive including 1.31, 1.50.1, and several others up to 1.58.6.
What type of attack can be launched using CVE-2008-5056?
An attacker can exploit CVE-2008-5056 to perform a cross-site scripting (XSS) attack, allowing for potential information theft or session hijacking.
Is CVE-2008-5056 easy to exploit?
Yes, CVE-2008-5056 can be exploited relatively easily through the manipulation of the department_id parameter in index.php.