CVE-2008-3596

Harmoni <1.4.7 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7 allows remote attackers to inject arbitrary web script or HTML via the Username field, which is inserted into logs that could be rendered when viewed by an administrator.

Scores

EPSS 0.0029
EPSS Percentile 51.6%

Classification

CWE
CWE-79
Status draft

Affected Products (44)

harmoni/harmoni < 1.4.6
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
... and 29 more

Timeline

Published Aug 12, 2008
Tracked Since Feb 18, 2026