Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-8935 - Vulnerability Database

Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-8935

Medium
Reference: CVE-2019-8935
Title: Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Collabtive 3.1 allows XSS via the manageuser.phpactionprofile id parameter.