Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2024-48706
Reference:
CVE-2024-48706
Title:
Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with actionadd or actioneditform within the (a) managemessage.php file and (b) managetask.php file respectively.