Sense of Security is one of Australia’s most trusted providers of cyber resilience, information security and risk management services.

Latest announcements
© Copyright Sense of Security

Security Advisory – SOS-09-005 – XOOPS Multiple Cross-Site Scripting Vulnerabilities

Release Date: 31-Jul-2009

Last Update:

Vendor Notification Date: 15-Jun-2009

Product: XOOPS

Platform: Independent

Affected versions: 2.3.3 (verified), possibly others

Severity Rating: Medium

Impact: Cookie/credential theft, impersonation, loss of

Attack Vector: Remote

Solution Status: Vendor patch

CVE reference: Not yet assigned


XOOPS is a content management system written in PHP. During an application penetration test Sense of Security identified that Input passed to the “op” parameter of viewpmsg.php, and in the query string of user.php are vulnerable to Cross-Site Scripting vulnerabilities. This occurred as a result of the application not properly filtering HTML tags which allowed malicious JavaScript to be embedded. When input is incorrectly validated and not properly sanitised and then displayed in a web page, attackers can trick users into viewing the web page and causing malicious code to be executed.

Please refer to the PDF version of this advisory for proof of concept code examples.


Vendor patch

Discovered By

Sense of Security Labs.

Our expert consultants are here to help you. For all your Cyber Security needs please contact us today.

No Comments

Sorry, the comment form is closed at this time.