Cross-Site Scripting in GetmeUK ContentTools via Image Handler Argument
A cross site scripting vulnerability exists in GetmeUK ContentTools up to version 1.6.16 within the Image Handler component. The vulnerability can be triggered remotely through manipulation of the onload argument. The issue has been publicly disclosed and potentially usable by attackers. The vulnerability has been rated as problematic, and despite early notification, the vendor did not provide a response to the security disclosure.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
getmeuk contenttools |
||
getcontenttools contenttools |