Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://huntr.dev/bounties/4311d8d7-682c-4f2a-b92c-3f9f1a36255a | exploit third party advisory patch |
https://github.com/pyload/pyload/commit/46d75a3087f3237d06530d55998938e2e2bda6bd | third party advisory patch |