CVE-2010-2463

UnknownEPSS 1.45%

Last modified

CVE-2010-2463 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.. EPSS estimates a 1.45% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.

Metrics

EPSS Probability
1.45%

70.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
JamroomJamroom<= 4.1.8
JamroomJamroom1.0
JamroomJamroom2.0.9
JamroomJamroom2.6.10
JamroomJamroom2.6.11
JamroomJamroom2.6.12
JamroomJamroom2.60
JamroomJamroom2.61
JamroomJamroom2.62
JamroomJamroom2.63
JamroomJamroom2.64
JamroomJamroom2.65
JamroomJamroom2.66
JamroomJamroom2.67
JamroomJamroom2.68
JamroomJamroom2.69
JamroomJamroom3.0
JamroomJamroom3.0.1
JamroomJamroom3.0.2
JamroomJamroom3.0.3
JamroomJamroom3.0.4
JamroomJamroom3.0.5
JamroomJamroom3.0.6
JamroomJamroom3.0.7
JamroomJamroom3.0.8
JamroomJamroom3.0.9
JamroomJamroom3.0.10
JamroomJamroom3.0.11
JamroomJamroom3.0.12
JamroomJamroom3.0.13
JamroomJamroom3.0.14
JamroomJamroom3.0.15
JamroomJamroom3.0.16
JamroomJamroom3.0.17
JamroomJamroom3.0.18
JamroomJamroom3.0.19
JamroomJamroom3.0.20
JamroomJamroom3.0.21
JamroomJamroom3.0.22
JamroomJamroom3.0.23
JamroomJamroom3.0.24
JamroomJamroom3.0.25
JamroomJamroom3.0.26
JamroomJamroom3.0.27
JamroomJamroom3.0.28
JamroomJamroom3.0.29
JamroomJamroom3.0.30
JamroomJamroom3.1.0
JamroomJamroom3.1.1
JamroomJamroom3.1.2

Showing 50 of 91 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-2463?
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.
How severe is CVE-2010-2463?
Severity scoring for CVE-2010-2463 is pending analysis. The EPSS model estimates a 1.45% probability of exploitation in the next 30 days.
How do I fix CVE-2010-2463?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-2463?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST