SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.soplanning.org | product |
https://www.sevenlayers.com/index.php/364-soplanning-v1-46-01-xss-session-hijack | third party advisory exploit |