Description
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Any version before 2.2.18
Credits
UwU
References
xenforo.com/...inc-xfmg-2-2-18-released-security-fix.235659/ (XenForo 2.3.9 (inc XFMG) & 2.2.18 Released (Security Fix))
www.vulncheck.com/...ss-site-scripting-via-lightbox-in-posts (VulnCheck Advisory: XenForo Cross-Site Scripting via Lightbox in Posts)