CVE-2008-3596
Harmoni <1.4.7 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Harmoni before 1.4.7 allows remote attackers to inject arbitrary web script or HTML via the Username field, which is inserted into logs that could be rendered when viewed by an administrator.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (44)
harmoni/harmoni
< 1.4.6
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
harmoni/harmoni
... and 29 more
Timeline
Published
Aug 12, 2008
Tracked Since
Feb 18, 2026