VULNERABILITY INTELLIGENCE

CVE-2002-2129

CVSS score4.3 MEDIUM
EPSS probability3.61%
CISA KEVNot currently listed
Published2002-12-31
Last modified2026-06-16

Description

Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.