Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) message, (2) name, (3) url, and (4) email parameters when commenting on a post. NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pixelpost | Pixelpost | 1.4.3 (including) | 1.4.3 (including) |
| Pixelpost | Pixelpost | 1.5_beta1 (including) | 1.5_beta1 (including) |