|
Xhawk.net Discussion BBCode IMG Tag Script Injection Vulnerability
The 'discussion' package from xhawk.net is prone to a script-injection vulnerability. An attacker can use BBCode IMG tags to trigger this issue and execute arbitrary code in a user's browser. Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for the theft of cookie-based authentication credentials. Other attacks are also possible. Version 2.0 beta2 of 'discussion' is reportedly prone to this vulnerability. |
|
|
Privacy Statement |