← Back to CVE List

CVE-2020-28141

Published: 2021-04-19T16:15Z
Last Modified: 2024-11-21T05:22Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt