MEDIUM
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string
Published Jan 10, 2018
6.1
MEDIUMCVSS 3.0
EPSS 0.84%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.