CVE-2019-16683: XSS
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16683?
CVE-2019-16683 is an issue discovered in the image-manager in Xoops 2.5.10, where a JavaScript payload executes when the breadcrumb showing the category name is hovered over while editing any image.
What is the severity of CVE-2019-16683?
The severity of CVE-2019-16683 is medium, with a severity score of 4.8.
Which software versions are affected by CVE-2019-16683?
Xoops version 2.5.10 is affected by CVE-2019-16683.
How can I fix CVE-2019-16683?
To fix CVE-2019-16683, apply the latest patch or upgrade to a newer version of Xoops.
Where can I find more information about CVE-2019-16683?
You can find more information about CVE-2019-16683 at the following references: [1](https://blog.nirajkhatiwada.com.np/cve-2019-16683-stored-cross-site-scripting/), [2](https://github.com/XOOPS/XoopsCore25/commits/master), [3](https://xoops.org/modules/publisher/)