Description
A cross-site scripting (XSS) vulnerability exists in LifeType 1.2.8 through the "newBlogUserName" parameter. The parameter value is reflected in the page without proper HTML encoding.
Impact
An attacker can inject malicious JavaScript that executes in an administrator's browser context, potentially allowing the creation of unauthorized accounts or privilege escalation.
Solution
Upgrade to the latest version of LifeType.