|
Koobi BBCode URL Tag Script Injection Vulnerability
Koobi is prone to a script injection vulnerability. An attacker can nest BBCode URL tags to trigger this issue and execute arbitrary code in a user's browser. Attacker-supplied HTML and script code would be able to access properties of the site, potentially allowing for theft of cookie-based authentication credentials. Other attacks are also possible. Koobi 5 is reportedly prone to this vulnerability. |
|
Privacy Statement |