The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-04-19T15:45:16

Updated: 2024-08-04T16:33:57.785Z

Reserved: 2020-11-02T00:00:00

Link: CVE-2020-28141

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-04-19T16:15:12.713

Modified: 2021-04-23T01:03:25.940

Link: CVE-2020-28141

cve-icon Redhat

No data.