Description
Vanilla before 2.6.1 allows XSS via the email field of a profile.
Remediation
References
Related Vulnerabilities
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Cross-Site Scripting (4.7.4)
Chamilo Improper Input Validation Vulnerability (CVE-2012-4030)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.14)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3834)
WordPress Plugin Simple Slideshow Manager Multiple Unspecified Vulnerabilities (2.1)