adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/pi-hole/adminlte/commit/f526716de7bb0fd382a64bcbbb33915c926f94bb | third party advisory patch |
https://huntr.dev/bounties/875a6885-9a64-46f3-94ad-92f40f989200 | issue tracking patch exploit third party advisory |