Description

A cross-site scripting (XSS) vulnerability exists in LifeType 1.2.8 through the "newBlogUserName" parameter. The parameter value is reflected in the page without proper HTML encoding.

Impact

An attacker can inject malicious JavaScript that executes in an administrator's browser context, potentially allowing the creation of unauthorized accounts or privilege escalation.

Solution

Upgrade to the latest version of LifeType.

References