The slideshow title was stored without sanitisation and later printed into the page without escaping. A user allowed to edit slideshows, such as an editor, could place JavaScript in the title and have it run in the browser of anyone who views the slideshow, even where unfiltered_html is not granted. This vulnerability affects the following... Weiterlesen
Intelligence View
Stored Cross-Site Scripting in MetaSlider Slideshow Title
The slideshow title was stored without sanitisation and later printed into the page without escaping. A user allowed to edit slideshows, such as an editor, could place JavaScript in the title and have it run in the browser of anyone who…
SOCIAL SHARE CARD GENERATOR