Description
Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 through 2.0.1 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in an IMG tag.
Affected products
- Xoops / xoops1.3.5 – 1.3.5
- Xoops / xoops1.3.6 – 1.3.6
- Xoops / xoops1.3.7 – 1.3.7
- Xoops / xoops1.3.8 – 1.3.8
- Xoops / xoops1.3.9 – 1.3.9
- Xoops / xoops2.0 – 2.0
- Xoops / xoops2.0.1 – 2.0.1