CVE-2007-6301

OpenNewsletter <2.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Manu · textwebappsphp
https://www.exploit-db.com/exploits/30853

Scores

EPSS 0.0551
EPSS Percentile 90.1%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

open_newsletter/open_newsletter < 2.5

Timeline

Published Dec 10, 2007
Tracked Since Feb 18, 2026