{
    "id": "CVE-2003-1278",
    "published": "2003-12-31 05:00:00",
    "last_modified": "2026-06-16 22:03:50",
    "cvss_score": "4.3",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
    "cwe": null,
    "description": "Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.",
    "epss_score": "0.03658",
    "epss_percentile": "0.89276",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-04 18:17:03",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "infopop",
            "product": "opentopic"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "22125",
            "title": "OpenTopic 2.3.1 - Private Message HTML Injection",
            "date": "2003-01-06",
            "url": "https://www.exploit-db.com/exploits/22125"
        }
    ],
    "refs_list": [
        "http://www.iss.net/security_center/static/10985.php",
        "http://www.securityfocus.com/archive/1/305232",
        "http://www.securityfocus.com/bid/6523",
        "http://www.iss.net/security_center/static/10985.php",
        "http://www.securityfocus.com/archive/1/305232",
        "http://www.securityfocus.com/bid/6523"
    ]
}