Description
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
Remediation
References
Related Vulnerabilities
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-1150)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0800)
MySQL CVE-2020-14852 Vulnerability (CVE-2020-14852)
WordPress Plugin Appointment Hour Booking-WordPress Booking Cross-Site Scripting (1.3.16)