CVE-2020-7050

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/02/2020
Last modified:
28/06/2022

Description

Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over accounts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codologic:codoforum:*:*:*:*:*:*:*:* 4.8.4 (including)