CVE-2010-2463

medium
Published 2010-06-25 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.3

Description

Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-34183 webapps php verified
High-Tech Bridge SA ยท 2010-06-21

Jamroom 4.0.2/4.1.x - 'forum.php' Cross-Site Scripting

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
jamroomjamroom3.2.0
jamroomjamroom3.1.4
jamroomjamroom{"endIncluding":"4.1.8"}
jamroomjamroom1.0
jamroomjamroom2.0.9
jamroomjamroom2.6.10
jamroomjamroom2.6.11
jamroomjamroom2.6.12
jamroomjamroom2.60
jamroomjamroom2.61
jamroomjamroom2.62
jamroomjamroom2.63
jamroomjamroom2.64
jamroomjamroom2.65
jamroomjamroom2.66
jamroomjamroom2.67
jamroomjamroom2.68
jamroomjamroom2.69
jamroomjamroom3.0
jamroomjamroom3.0.1
jamroomjamroom3.0.2
jamroomjamroom3.0.3
jamroomjamroom3.0.4
jamroomjamroom3.0.5
jamroomjamroom3.0.6
jamroomjamroom3.0.7
jamroomjamroom3.0.8
jamroomjamroom3.0.9
jamroomjamroom3.0.10
jamroomjamroom3.0.11
jamroomjamroom3.0.12
jamroomjamroom3.0.13
jamroomjamroom3.0.14
jamroomjamroom3.0.15
jamroomjamroom3.0.16
jamroomjamroom3.0.17
jamroomjamroom3.0.18
jamroomjamroom3.0.19
jamroomjamroom3.0.20
jamroomjamroom3.0.21
jamroomjamroom3.0.22
jamroomjamroom3.0.23
jamroomjamroom3.0.24
jamroomjamroom3.0.25
jamroomjamroom3.0.26
jamroomjamroom3.0.27
jamroomjamroom3.0.28
jamroomjamroom3.0.29
jamroomjamroom3.0.30
jamroomjamroom3.1.0
jamroomjamroom3.1.1
jamroomjamroom3.1.2
jamroomjamroom3.1.3
jamroomjamroom3.1.5
jamroomjamroom3.2.1
jamroomjamroom3.2.2
jamroomjamroom3.2.3
jamroomjamroom3.2.4
jamroomjamroom3.2.5
jamroomjamroom3.2.6
jamroomjamroom3.3.0
jamroomjamroom3.3.1
jamroomjamroom3.3.2
jamroomjamroom3.3.3
jamroomjamroom3.3.4
jamroomjamroom3.3.5
jamroomjamroom3.3.6
jamroomjamroom3.3.7
jamroomjamroom3.3.8
jamroomjamroom3.4.0
jamroomjamroom4.0.2
jamroomjamroom4.0.3
jamroomjamroom4.0.4
jamroomjamroom4.0.5
jamroomjamroom4.0.6
jamroomjamroom4.0.7
jamroomjamroom4.0.8
jamroomjamroom4.0.9
jamroomjamroom4.0.10
jamroomjamroom4.0.11
jamroomjamroom4.0.12
jamroomjamroom4.0.13
jamroomjamroom4.0.14
jamroomjamroom4.1.0
jamroomjamroom4.1.1
jamroomjamroom4.1.2
jamroomjamroom4.1.3
jamroomjamroom4.1.4
jamroomjamroom4.1.5
jamroomjamroom4.1.6
jamroomjamroom4.1.7

References

CWEs

CWE-79

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.