Description
Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.
Remediation
References
Related Vulnerabilities
Envoy Proxy CVE-2024-45807 Vulnerability (CVE-2024-45807)
WordPress Plugin WP Customer Area Cross-Site Request Forgery (8.1.3)
Apache HTTP Server Incorrect Authorization Vulnerability (CVE-2014-8109)
WordPress Other Vulnerability (CVE-2004-1584)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3848)