|
FlatNuke contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the content of news items upon submission to a moderator. This could allow a user to create a specially crafted new item that would execute arbitrary code in a moderator's browser within the trust relationship between the browser and the server, possibly allowing an attacker to steal authentication cookies or other information of a privileged account, leading to a loss of integrity.
|