Description
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin AJAX Post Search 'srch_txt' Parameter SQL Injection (1.2)
Jboss EAP Improper Input Validation Vulnerability (CVE-2020-1732)
Drupal Core 4.6.x Form Action Attribute Injection (4.6.0 - 4.6.9)
WordPress Plugin Poll Maker SQL Injection (3.2.0)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3838)