CVE-2019-18839
CRITICALFUDForum 3.0.9 - XSS
Title source: llmDescription
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.
Exploits (1)
Scores
CVSS v3
9.0
EPSS
0.0181
EPSS Percentile
82.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-78
CWE-79
Status
published
Products (1)
fudforum/fudforum
3.0.9
Published
Nov 13, 2019
Tracked Since
Feb 18, 2026