Description
An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered over while editing any image, a JavaScript payload executes.
Remediation
References
Related Vulnerabilities
WordPress Plugin Recommend to a friend Cross-Site Scripting (2.0.2)
Moodle Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2020-14322)
Oracle HTTP Server CVE-2020-2545 Vulnerability (CVE-2020-2545)
Drupal Core 5.x Cross-Site Request Forgery (5.0 - 5.2)
Oracle Database Server CVE-2010-0852 Vulnerability (CVE-2010-0852)