CVE-2022-39027

Publication date

2022-10-31 06:40:39

Family

twcert

State

PUBLISHED

Description

U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.