This is a vulnerability writeup describing a persistent XSS vulnerability in PBBoard v2.1.4 CMS, where malicious script code can be injected into the 'answer field' of a poll within a thread. The writeup includes a proof of concept demonstrating the exploitation technique.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:PBBoard v2.1.4 CMS
Auth required
Prerequisites:Low-privileged user account · User interaction to view the malicious thread