Description
|
|
(#A cross-site scripting vulnerability was reported in Pligg CMS.#A remote attacker could exploit it by enticing their victim into following a specially formed link in order to execute arbitrary JavaScript or HTML code.##This vulnerability is due to an improper input sanitization to the "keyword" parameter located in the "groups.php" script page.##A proof of concept is available.##Updated, 22/12/2016:#The pligg packages provided by FreeBSD are vulnerable.)
|