Ninja Forms before 3.14.1 output the Success Message action without HTML sanitisation and did not escape merge-tag values (such as submitted field values) inserted into it. An attacker can submit form input containing script markup that is rendered in the browser when the success message is displayed. The fix sanitises the message with... Weiterlesen
Intelligence View
Cross-Site Scripting in Ninja Forms Success Message Action
Ninja Forms before 3.14.1 output the Success Message action without HTML sanitisation and did not escape merge-tag values (such as submitted field values) inserted into it. An attacker can submit form input containing script markup that is…
SOCIAL SHARE CARD GENERATOR