An issue exists in DataLife Engine (DLE) up to and including 13.0. An attacker can use XSS (related to the /addnews.html and /index.php?do=addnews URIs) to send a malicious script to unsuspecting Admins or users.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
dleviet datalife engine |