GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board head contents" parameter, aka the adm/boardformupdate.php bomobilecontent_head parameter.
{
"cpe": "cpe:2.3:a:sir:gnuboard:5.3.1.9:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "5.3.1.9"
},
{
"last_affected": "5.3.1.9"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
]
}