Description
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
Remediation
References
Related Vulnerabilities
WordPress Plugin Donorbox-Free Recurring Donation Form Cross-Site Scripting (7.1.1)
WordPress Plugin Broken Link Manager Cross-Site Scripting (0.5.5)
WordPress Plugin AJS Instagram Feed Cross-Site Scripting (1.0)
WordPress Plugin Slideshow Gallery LITE Multiple Vulnerabilities (1.5.1)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4193)