CVE-2020-28141

MEDIUM

Online Discussion Forum - XSS

Title source: rule
STIX 2.1

Description

The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.

Exploits (1)

exploitdb WORKING POC
by j5oh · textwebappsphp
https://www.exploit-db.com/exploits/48897

Scores

CVSS v3 5.4
EPSS 0.0052
EPSS Percentile 66.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
online_discussion_forum_project/online_discussion_forum 1.0
Published Apr 19, 2021
Tracked Since Feb 18, 2026