A cross-site scripting vulnerability exists in Citadel versions prior to 994. When a malicious user sends an instant message with some JavaScript code, the script may be executed on the web browser of the victim user.
{ "binaries": [ { "binary_version": "9.01-dfsg-1", "binary_name": "citadel-suite" }, { "binary_version": "9.01-dfsg-1", "binary_name": "citadel-webcit" } ] }
{ "binaries": [ { "binary_version": "917-dfsg-2", "binary_name": "citadel-suite" }, { "binary_version": "917-dfsg-2", "binary_name": "citadel-webcit" } ] }
{ "binaries": [ { "binary_version": "917-dfsg-4", "binary_name": "citadel-suite" }, { "binary_version": "917-dfsg-4", "binary_name": "citadel-webcit" } ] }