Site icon API Security Blog

MainWP: Reflected XSS in “Manage Tags” Notes Field

image
A reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field under the Manage Tags section. Arbitrary input entered into this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output…Read More

Exit mobile version