This is an old revision of this page, as edited April 18, 2015, 10:26 AM by pegasus(contribs). It may differ significantly from the current revision.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.
Common Name PM Hijack Vulnerability VWE-ID PM Hijack Vulnerability Related Report None Severity MEDIUM Exploit Difficulty NORMAL Platform Affects all platforms supported by the vulnerable versions. Description HTML/Javascript injection.
Discovered May 6, 2009 Resolved May 10, 2009 Patches Available 2.3.0 Workaround Update permissions so that untrusted users cannot send private messages.