Ninja Forms before 3.10.1 does not sanitise or escape several form-field settings before storing them, so an administrator can inject arbitrary JavaScript even when the unfiltered_html capability is disallowed. On multisite installations this lets a site administrator run script in the browser of any user who views or edits the affected form,... Weiterlesen
Intelligence View
Authenticated (Admin+) Stored Cross-Site Scripting in Ninja Forms Field Settings
Ninja Forms before 3.10.1 does not sanitise or escape several form-field settings before storing them, so an administrator can inject arbitrary JavaScript even when the unfiltered_html capability is disallowed. On multisite installations…
SOCIAL SHARE CARD GENERATOR