CVE-2011-4565: XSS
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextareapreview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4565?
CVE-2011-4565 has been classified as a medium severity vulnerability due to its potential for various cross-site scripting (XSS) attacks.
How do I fix CVE-2011-4565?
To fix CVE-2011-4565, upgrade to a version of XOOPS that is not affected by this vulnerability, such as version 2.5.2 or later.
What software versions are affected by CVE-2011-4565?
CVE-2011-4565 affects multiple versions of XOOPS, including 2.0.13.2, 2.3.0, and versions up to and including 2.5.1.a.
What types of vulnerabilities are included in CVE-2011-4565?
CVE-2011-4565 includes multiple cross-site scripting (XSS) vulnerabilities that allow attackers to inject arbitrary web scripts or HTML.
How can CVE-2011-4565 be exploited?
CVE-2011-4565 can be exploited by sending crafted messages or requests through vulnerable parameters like 'text' or 'message' in the XOOPS application.