Description
Multiple cross-site scripting (XSS) vulnerabilities exist in Mambo CMS version 4.6.2. Various input parameters throughout the application are not properly sanitized before being rendered in HTML pages.
Impact
Attackers can inject malicious scripts that execute when administrators or users view affected pages, enabling session hijacking, credential theft, and potential administrative account compromise.
Solution
Upgrade to the latest version of Mambo or migrate to a supported CMS fork such as Joomla.