Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script via (1) the member parameter to member.php or (2) the action parameter to buddy.php.
| Software | From | Fixed in |
|---|---|---|
| xmb_forum / xmb | 1.8 | 1.8.x |