Description
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php file.
Remediation
References
Related Vulnerabilities
WordPress Plugin Resume Submissions & Job Postings Arbitrary File Upload (2.5.1)
Liferay Portal Deserialization of Untrusted Data Vulnerability (CVE-2019-16891)
MySQL CVE-2023-22112 Vulnerability (CVE-2023-22112)
WordPress Plugin Photoracer Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.0)