Monstra CMS through 3.0.4 has XSS in the title function in plugins/box/pages/pages.plugin.php via a page title to admin/index.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/monstra-cms/monstra/commit/388ab412035474068758df6b07e7e06852f3747b | third party advisory patch |
https://github.com/monstra-cms/monstra/issues/427 | third party advisory exploit |