Description
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page, aka the manageuser.php?action=edit address1 parameter.
Remediation
References
Related Vulnerabilities
Envoy Proxy Integer Overflow or Wraparound Vulnerability (CVE-2021-28682)
phpMyFAQ Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-6048)
WordPress 4.1.x Possible SQL Injection Vulnerability (4.1 - 4.1.19)
WordPress Plugin Advanced File Manager Information Disclosure (5.2.4)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-7537)