Description

A cross-site scripting (XSS) vulnerability exists in LifeType 1.2.7 through the "searchTerms" parameter. Search terms are displayed in the page without proper output encoding.

Impact

An attacker can craft a malicious search link that, when followed by another user, executes arbitrary JavaScript in their browser, enabling cookie theft and session hijacking.

Solution

Upgrade to the latest version of LifeType.

References