CVE-2008-3874

Lussumo Vanilla <1.1.5-rc1 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==> Value pairs). NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0034
EPSS Percentile 56.0%

Classification

CWE
CWE-79
Status draft

Affected Products (11)

lussumo/vanilla < 1.1.5-rc1
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla
lussumo/vanilla

Timeline

Published Aug 29, 2008
Tracked Since Feb 18, 2026