J-Security Center

Title: XMB Forum Member.PHP U2U Private Message HTML Injection Vulnerability

Severity: MODERATE

Description:

XMB Forum 1.8 is a web based discussion forum.

A vulnerability has been reported for XMB Forum 1.8 which may make it prone to HTML injection attacks. The problem is said to occur while viewing U2U private messages.

Specifically, U2U private messages may not be sufficiently sanitized of malicious content. This may make it possible for an attacker to place HTML or script code within the message body of a private U2U message for another user. When the legitimate forum user attempts to view the message the malicious code will be interpreted by their browser in the security context of the forum website.

Attackers may potentially exploit this issue to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.

Affected Products:

  • XMB Forum 1.8.0
  • XMB Forum 1.8.0SP1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.