4.3
CVSSv2

CVE-2012-6555

Published: 23/05/2013 Updated: 09/11/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote malicious users to inject arbitrary web script or HTML via the discussion title.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vanillaforums latestcomment 1.1

Exploits

# Title: Vanilla LatestComment 11 Plugin Persistant XSS Vulnerability # Date: 18/5/12 # Author: Henry Hoggard # Author URL: henryhoggardcouk # Author Twitter: @henryhoggard # Software: Vanilla Version 20184 + Latest Comment 11 #vanillaforumsorg/addon/latestcomment-plugin # vanillaforumsorg ################################## ...