Description
An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is hovered over in the list or in the Edit page, the payload executes.
Remediation
References
Related Vulnerabilities
WordPress Plugin Controlled Admin Access Security Bypass (1.4.0)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0060)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-43952)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-4306)
WordPress Plugin Mang Board WP Unspecified Vulnerability (2.0.5)