Back

CVE-2002-1458

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is on, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, (3) Subject and (4) Body.

Published: Jun 9, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
leszek_krupinski l-forum 2.4.0

GitHub Security Advisory GHSA-h4fq-xm38-wf33

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.63%

Top 26% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub