Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:28

Updated: 2022-10-03T16:15:28

Reserved: 2022-10-03T00:00:00


Link: CVE-2012-6623

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-01-16T21:55:44.487

Modified: 2014-04-23T14:35:31.593


Link: CVE-2012-6623

JSON object: View

cve-icon Redhat Information

No data.

CWE