Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file respectively.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-48706.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "3.1" } ] } ]