Cross site scripting (XSS) vulnerability in kfm through 1.4.7 via crafted GET request to /kfm/index.php.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://code.google.com/archive/p/kfm/downloads | product |
https://cxsecurity.com/issue/WLB-2022090057 | third party advisory exploit |