CVE-2018-15580 describes a Cross-Site Scripting (XSS) vulnerability in the adm/contentformupdate.php component of gnuboard5 versions prior to 5.3.1.6. This flaw allows remote attackers to inject arbitrary web scripts or HTML, impacting the integrity and potentially the confidentiality of user sessions. Rated as MEDIUM with a CVSS score of 6.1, exploitation requires user interaction (UI:R) but can be executed with low attack complexity (AC:L) over the network (AV:N). There is no evidence of active exploitation (KEV: No), nor are there any known public exploit codes like Metasploit or Nuclei modules. The vulnerability has garnered minimal community attention, with no social media discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.3.1.6CPE matchmatch criteria | cpe:2.3:a:sir:gnuboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.