Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over accounts.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-28184 Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over accounts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T09:18:02.696Z

Reserved: 2020-01-14T00:00:00

Link: CVE-2020-7050

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-15T18:19:50.890

Modified: 2024-11-21T05:36:33.903

Link: CVE-2020-7050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.