A cross-site scripting (XSS) vulnerability exists in Mini CMS V1.11. The vulnerability exists in the article upload: post-edit.php page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/bg5sbk/MiniCMS | product third party advisory |
http://minicms.com | not applicable broken link |
https://github.com/bg5sbk/MiniCMS/issues/41 | third party advisory exploit |