CVE-2012-6671: Dragonbyte-Tech Forumon Rpg Module
Medium severity, CVSS 6.1. EPSS: 1.6% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary web script or HTML via the (1) monster[title] or (2) monster[description] parameters.
Affected products
- Dragonbyte-Tech Forumon Rpg Module: before 1.0.8 (fixed in 1.0.8)
Published 2018-01-11. Last modified 2026-06-16.