Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://syhack.wordpress.com/2019/09/29/ilch-content-management-system-v-2-1-22-vulnerability-disclosure/ | third party advisory exploit |