CVE-2019-18839

Source
https://cve.org/CVERecord?id=CVE-2019-18839
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18839.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-18839
Published
2019-11-13T15:15:10.260Z
Modified
2026-04-10T04:17:04.387218Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

References

Affected packages

Git / github.com/fudforum/fudforum

Affected ranges

Type
GIT
Repo
https://github.com/fudforum/fudforum
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.9"
        }
    ]
}

Affected versions

Other
fud3_0_9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18839.json"