Cross-site scripting (XSS) vulnerability in phpReview 0.9.0 rc2 and earlier allows remote attackers to inject arbitrary web script or HTML via user-submitted reviews.
| Software | From | Fixed in |
|---|---|---|
| hans_wolters / phpreview | 0.9_final | 0.9_final.x |
| hans_wolters / phpreview | 0.2.1 | 0.2.1.x |
| hans_wolters / phpreview | 0.1 | 0.1.x |
| hans_wolters / phpreview | 0.9_rc2 | 0.9_rc2.x |
| hans_wolters / phpreview | 0.2 | 0.2.x |
| hans_wolters / phpreview | 0.9_rc1 | 0.9_rc1.x |