CVE-2018-15585

MEDIUM

GNUBOARD5 < 5.3.1.6 - Cross-Site Scripting via Popup Title Parameter

Title source: llm
STIX 2.1

Description

Cross-Site Scripting (XSS) vulnerability in newwinform.php in GNUBOARD5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML via the popup title parameter.

Scores

CVSS v3 6.1
EPSS 0.0152
EPSS Percentile 71.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
sir/gnuboard < 5.3.1.6
Published Mar 27, 2019
Tracked Since Feb 18, 2026