CVE-2008-3874
Lussumo Vanilla <1.1.5-rc1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==> Value pairs). NOTE: some of these details are obtained from third party information.
References (7)
Scores
EPSS
0.0034
EPSS Percentile
56.0%
Classification
CWE
CWE-79
Status
draft
Affected Products (11)
lussumo/vanilla
< 1.1.5-rc1
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
Timeline
Published
Aug 29, 2008
Tracked Since
Feb 18, 2026