CVE-2019-16684 describes a stored cross-site scripting (XSS) vulnerability in the image-manager component of Xoops version 2.5.10. An authenticated attacker with privileges to upload images can embed a JavaScript payload within an image's filename. This payload executes when a user hovers over the malicious image in the image list or edit page. This vulnerability has a CVSS score of 4.8 (Medium), indicating a low attack complexity but requiring high privileges and user interaction. The potential impact includes limited confidentiality and integrity compromise, as an attacker could execute arbitrary scripts in the victim's browser. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting low public awareness and limited attacker interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.10CPE matchmatch criteria | cpe:2.3:a:xoops:xoops:2.5.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.