First published: Mon Apr 19 2021(Updated: )
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Itsourcecode Online Discussion Forum Project in PHP with Source Code | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28141 is considered a high severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2020-28141, update the Online Discussion Forum to a version that includes a patch addressing the XSS vulnerability.
Authenticated users of Online Discussion Forum 1.0 are impacted by CVE-2020-28141 as they can inadvertently execute malicious scripts.
CVE-2020-28141 allows attackers to perform cross-site scripting (XSS) attacks through crafted messages sent to other users.
Yes, CVE-2020-28141 poses a risk to user data as it can be exploited to steal session cookies or perform actions on behalf of users.