Description
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
Remediation
References
Related Vulnerabilities
WordPress Plugin wpForo Forum Open Redirect (1.9.6)
WordPress Plugin BannerMan Cross-Site Scripting (0.2.4)
WordPress Plugin Sendit WP Newsletter SQL Injection (2.5.1)
WordPress Plugin WPS Hide Login Security Bypass (1.5.4.2)
WordPress Plugin RSS Redirect & Feedburner Alternative Unspecified Vulnerability (1.9)