Unrated severityNVD Advisory· Published Aug 22, 2008· Updated Apr 23, 2026
CVE-2008-3773
CVE-2008-3773
Description
Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]).
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- marc.infonvdPatch
- www.coresecurity.com/content/vbulletin-cross-site-scripting-vulnerabilitynvdPatch
- www.vbulletin.com/forum/showthread.phpnvdPatch
- secunia.com/advisories/31552nvdVendor Advisory
- securityreason.com/securityalert/4182nvd
- www.securityfocus.com/bid/30777nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44576nvd
News mentions
0No linked articles in our index yet.