Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 101 bronnen 1 kritiek 35 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-2021

LOW · 3.5 CVSS Gepubliceerd: CWE-79

Beschrijving

Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

Vendors

Vbulletin

Affected products

Vbulletin

References