Description
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message). NOTE: some of these details are obtained from third party information.
Remediation
References
Related Vulnerabilities
Grafana Improper Synchronization Vulnerability (CVE-2023-2801)
Nexus Repository Manager Incorrect Default Permissions Vulnerability (CVE-2019-9630)
MySQL CVE-2017-10320 Vulnerability (CVE-2017-10320)
MySQL CVE-2024-21159 Vulnerability (CVE-2024-21159)
Grafana Incorrect Authorization Vulnerability (CVE-2022-31107)