Description
Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB before 3.0.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2021-2175 Vulnerability (CVE-2021-2175)
WordPress Plugin HashThemes Demo Importer Security Bypass (1.1.1)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-10188)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-32731)