Cross-site scripting (XSS) vulnerability in forum.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to inject arbitrary HTML or web script via the name parameter.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Open_tibia_server_cms | Open_tibia_server_cms | 2.0 (including) | 2.0 (including) | 
| Open_tibia_server_cms | Open_tibia_server_cms | 2.1.3 (including) | 2.1.3 (including) | 
| Open_tibia_server_cms | Open_tibia_server_cms | 2.1.4 (including) | 2.1.4 (including) | 
| Open_tibia_server_cms | Open_tibia_server_cms | 2.1.5 (including) | 2.1.5 (including) |