MidnightBSD

Advisories for easyxdm

CVE-2014-1403 MEDIUM

Cross-site scripting (XSS) vulnerability in name.html in easyXDM before 2.4.19 allows remote attackers to inject arbitrary web script or HTML via the location.hash value.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
easyxdm easyxdm *
easyxdm easyxdm 2.3.3
easyxdm easyxdm 2.4.4
easyxdm easyxdm 2.3.2
easyxdm easyxdm 2.4.1
easyxdm easyxdm 2.4.2
easyxdm easyxdm 2.4.3
easyxdm easyxdm 2.4.5
easyxdm easyxdm 2.4.6
easyxdm easyxdm 2.4.0