Description
|
|
A vulnerability has been reported in Wallpaper script, which can be exploited by malicious people to conduct script insertion attacks.
Input passed via the "name" parameter when uploading or editing a wallpaper is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed.
The vulnerability is reported in version 3.5.0082. Other versions may also be affected.
|