Cross-site scripting (XSS) vulnerability in 4images 1.7.7...
Low severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Jun 19, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Jan 31, 2023
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture.
References