MEDIUM
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs
Published Jun 6, 2017
6.1
MEDIUMCVSS 3.0
EPSS 0.74%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.