cleantalk
Vulnerabilities and Security Researches

Advanced ads Management by Inazo, 63dad79a-aa7a-4607-afe4-e1c218b31da6

Published on
-
Research Description
Advanced ads Management by Inazo [inazo-advanced-ads-management] < 1.4 Advanced ads Management &lt;= 1.3 - Authenticated Stored Cross-Site Scripting (XSS) Any authenticated user, including authors, can embed JavaScript via the &#039;HTML Codes&#039; functionality when creating a new add. Embedding JavaScript should be restricted to users with the &#039;unfiltered_html&#039; capability.
Affected versions
max 1.4.
Status
vulnerable