Skip to content
ביקורת אבטחה
חזרה ללוח
D40אומת בקודP1

Stored XSS in admin dashboards (guests/tickets/leads) + reflected XSS in seatgen

C · authS2 · active-safeSECT1
תיקון
90%
מורכבות low

Several admin dashboards render buyer input unescaped, allowing stored and reflected cross-site scripting.

guests.php:208, init.php:982, seatgen.php:29