cleantalk
Vulnerabilities and Security Researches

Football Pool, CVE-2024-29802

CVE, Research URL

CVE-2024-29802

Application

Football Pool

Published on
Mar 27, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Antoine Hurkmans Football Pool allows Stored XSS.This issue affects Football Pool: from n/a through 2.11.3.
Affected versions
max 2.11.4.
Status
vulnerable