"value":"Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field."
},
{
"lang":"es",
"value":"Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en memcp.php en XMB U2U Instant Messenger permite a usuarios autenticados remotamente inyectar secuencias de comandos web o HTML de su elecci\u00f3n a trav\u00e9s del campo recipient (receptor)."
}
],
"vendorComments":[
{
"organization":"XMB",
"comment":"As noted in https://docs.xmbforum2.com/index.php?title=Security_Issue_History XMB version 1.9.10 or later must be installed to prevent attacks described by this CVE. All earlier versions of XMB are vulnerable until upgraded. Upgrades are available at https://www.xmbforum2.com/",