peter bassill · operator
$ cve CVE-2003-1278 JSON

CVE-2003-1278 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.7% (pctl 89)

Patch early

A public exploit exists.

Description

Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.66% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2003-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
infopopopentopic

Public exploits

SourceTitleDate
exploit-dbOpenTopic 2.3.1 - Private Message HTML Injection2003-01-06

References

→ the Explorer  ·  watch your stack  ·  NVD