Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.
| Software | From | Fixed in |
|---|---|---|
| powie / pforum | 1.13 | 1.13.x |
| powie / pforum | 1.14 | 1.14.x |
| powie / pforum | 1.12 | 1.12.x |
| powie / pforum | 1.11 | 1.11.x |