Executive brief
UBB.threads, a forum and community software platform, is vulnerable to a security flaw that could allow attackers to run malicious scripts in a user's browser. By tricking a victim into clicking a specially crafted link, an attacker could potentially steal session information or perform actions on the user's behalf. This issue is particularly concerning as the vendor has not responded to reports, and a fix may not be available.
Technical details
UBB.threads (confirmed in version 7.7.5 and likely earlier) is vulnerable to Reflected Cross-Site Scripting (XSS) because the application improperly sanitizes user-supplied input in certain HTTP requests. An unauthenticated remote attacker can exploit this by convincing a user to click a malicious URL containing a crafted payload. If successful, the attacker can execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch has been confirmed.
Affected products
- UBB Systems UBB.threads All versions through 7.7.5
Timeline
- 2026-06-18: advisory: Initial disclosure by CERT Polska