Description
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
Remediation
References
Related Vulnerabilities
WordPress Plugin FunCaptcha-Anti-Spam CAPTCHA Cross-Site Request Forgery (0.3.2)
Oracle Database Server CVE-2009-3413 Vulnerability (CVE-2009-3413)
WordPress Plugin Icon Widget Cross-Site Scripting (1.2.6)
Oracle Application Server Other Vulnerability (CVE-2004-2134)
WordPress Plugin Product Catalog Multiple Vulnerabilities (3.1.2)