Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-3298 - Vulnerability Database
Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-3298
Medium
Reference:
CVE-2021-3298
Title:
Collabtive Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Collabtive 3.1 allows XSS when an authenticated user enters an XSS payload into the address section of the profile edit page aka the manageuser.phpactionedit address1 parameter.