The persistent i*nput validation vulnerabilities can be exploited by remote attackers with low privileged
user account & required user inter a*ction. For demonstration or reproduce ...
To reproduce the vulnerability, the attacker should add a new thread and the check on the add poll button. After that
the attacker can add his malicious code in the answer field of the poll. Anyone who's viewing that thread will be
exploited by the malicious code. Such attack can result in session hijacking, redirecting or c*ookie theft. Moreover,
the persistent XSS can be exploited to launch a CSRF attack to the user and to exploit the other CSRF vulnerabilities.
Download Patch to version 2.1.4