An issue exists in PHPMyWind 5.5. The username parameter of the /install/index.php page has a stored Cross-site Scripting (XSS) vulnerability, as demonstrated by admin/login.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpmywind phpmywind |