adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/fa38c61f-4043-4872-bc85-7fe5ae5cc2e8 | patch exploit third party advisory issue tracking |
https://github.com/pi-hole/adminlte/commit/f526716de7bb0fd382a64bcbbb33915c926f94bb | third party advisory patch |