First published: Mon Mar 22 2021(Updated: )
An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authentication) injecting arbitrary JavaScript into any forum message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | <1.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28968 is classified as a medium severity XSS vulnerability.
To fix CVE-2021-28968, upgrade PunBB to version 1.4.6 or later.
PunBB versions prior to 1.4.6 are affected by CVE-2021-28968.
CVE-2021-28968 allows attackers to inject arbitrary JavaScript into forum messages, leading to potential cross-site scripting attacks.
Yes, authentication is required to exploit CVE-2021-28968.