Site icon API Security Blog

MainWP: Reflected XSS in “Cost Tracker” Notes Field

image
The reflected Cross-Site Scripting (XSS) vulnerability was discovered in the "Notes" input field of the Cost Tracker section in MainWP (Version 5.4.0.11). Arbitrary user input in this field was reflected back and executed immediately upon saving, due to the lack of proper input sanitization and output…Read More

Exit mobile version