Executive brief
Wikidforum, a hybrid forum and wiki platform, contains a security flaw that allows users to inject malicious scripts into forum replies. An attacker with a standard account can post a comment that, when viewed by other users or administrators, executes hidden code in their web browser. This could lead to unauthorized actions being performed on behalf of the victim, such as account hijacking or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Wikidforum 2.20 due to improper neutralization of user-provided input in the 'reply_text' parameter. An authenticated attacker can send a specially crafted request to the 'rpc.php' endpoint containing malicious JavaScript. Because the application fails to adequately sanitize this input before storing it and displaying it to other users, the script executes in the context of any user who views the affected forum reply. This can be used to steal session cookies or perform unauthorized actions in the victim's browser. The vulnerability is tracked as CWE-79.
Affected products
- Wikidforum Wikidforum 2.20
Timeline
- 2018-10-10: other: Exploit-DB proof of concept published
- 2026-05-29: advisory: NVD/VulnCheck advisory published