Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the module parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
bigtreecms bigtree cms 4.0 |
||
bigtreecms bigtree cms |