CVE-2011-4565

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.5.1.a, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to include/formdhtmltextarea_preview.php or (2) img BBCODE tag within the message parameter to pmlite.php (aka Private Message).  NOTE: some of these details are obtained from third party information.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
xoopsxoops
𝑥
≤ 2.5.1.a
xoopsxoops
2.0.2
xoopsxoops
2.0.13.2
xoopsxoops
2.0.14
xoopsxoops
2.0.14:rc1
xoopsxoops
2.0.15
xoopsxoops
2.0.16
xoopsxoops
2.0.17
xoopsxoops
2.0.17.1
xoopsxoops
2.0.17.1:rc
xoopsxoops
2.0.17.1:rc2
xoopsxoops
2.0.18
xoopsxoops
2.0.18:rc
xoopsxoops
2.0.18.1
xoopsxoops
2.0.18.1:rc
xoopsxoops
2.0.18.2
xoopsxoops
2.3.0
xoopsxoops
2.3.1
xoopsxoops
2.3.2a:a
xoopsxoops
2.3.2b:b
xoopsxoops
2.3.3
xoopsxoops
2.3.3b:b
xoopsxoops
2.4.0
xoopsxoops
2.4.1
xoopsxoops
2.4.2
xoopsxoops
2.4.3
xoopsxoops
2.4.4
xoopsxoops
2.4.5
xoopsxoops
2.5.0
xoopsxoops
2.5.1
𝑥
= Vulnerable software versions