Description
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
Remediation
References
Related Vulnerabilities
WordPress Plugin MDC YouTube Downloader Local File Inclusion (2.1.0)
Jenkins Missing Authorization Vulnerability (CVE-2024-43045)
Dotclear Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1584)
MySQL CVE-2016-5612 Vulnerability (CVE-2016-5612)
WordPress 4.0.x Denial of Service Vulnerability (4.0 - 4.0.22)