CVE-2018-18678

Publication date

2019-10-30 17:58:11

Family

mitre

State

PUBLISHED

Description

GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter.