=============================================================================== | | ____ _ __ ___ __ __/ / /__ ___ ______ ______(_) /___ __ / _ \/ // / / (_-alert('xss'); --- SNIP --- If the message has been sent successfully a alert diolog will apear containing xss when an user checks there message in the dashboard. IMPACT ====== An attacker could potentially hijack session authentication tokes of remote users and leverage the vulnerability to increase the attack vector to the underlying software and operating system of the victim. THREAT LEVEL ============ High STATUS ====== 0day DISCLAIMER ========== nullsecurity.net hereby emphasize, that the information which is published here are for education purposes only. nullsecurity.net does not take any responsibility for any abuse or misusage!