Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.fifthplay.com/faq/ | product |
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5561.php | third party advisory |