CVE-2021-29399

XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:xmbforum2:xmb:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:5.0.0:-:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:xmbforum2:xmb:*:*:*:*:*:*:*:*
cpe:2.3:a:xmbforum2:xmb:*:*:*:*:*:*:*:*
OR cpe:2.3:a:php:php:7.0.0:-:*:*:*:*:*:*
cpe:2.3:a:php:php:8.0.0:-:*:*:*:*:*:*

Information

Published : 2021-04-19 05:15

Updated : 2021-04-22 13:07


NVD link : CVE-2021-29399

Mitre link : CVE-2021-29399


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

php

  • php

xmbforum2

  • xmb