Description
Vanilla before 2.6.1 allows XSS via the email field of a profile.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3455 Vulnerability (CVE-2017-3455)
Drupal Improper Input Validation Vulnerability (CVE-2012-1589)
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.20)
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2032)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-0362)