XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xmb Forum
Xmb Forum xmb Xmbforum2 Xmbforum2 xmb |
|
| Vendors & Products |
Xmb Forum
Xmb Forum xmb Xmbforum2 Xmbforum2 xmb |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered. | |
| Title | XMB Forum 1.9.12.06 Persistent Cross-Site Scripting via Admin Templates | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-11T21:35:30.698Z
Updated: 2025-12-11T21:35:30.698Z
Reserved: 2025-12-11T00:58:28.456Z
Link: CVE-2024-58292
No data.
Status : Received
Published: 2025-12-11T22:15:50.107
Modified: 2025-12-11T22:15:50.107
Link: CVE-2024-58292
No data.