Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticated users to inject arbitrary web script or HTML via the search parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
x3cms x3 cms 0.5.1 |
||
x3cms x3 cms 0.5.1.1 |