Back

CVE-2002-1459

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages" option is off, allows remote attackers to insert arbitrary script or HTML via message fields including (1) From, (2) E-Mail, and (3) Subject.

Published: Jun 9, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
leszek_krupinski l-forum 2.4.0

GitHub Security Advisory GHSA-23j3-qh8r-rpx6

Cross-site scripting vulnerability in L-Forum 2.40 and earlier, when the "Enable HTML in messages...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.63%

Top 26% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub