חזרה ללוח
D40אומת בקודP1
Stored XSS in admin dashboards (guests/tickets/leads) + reflected XSS in seatgen
C · authS2 · active-safeSECT1
תיקון
מורכבות low90%
Several admin dashboards render buyer input unescaped, allowing stored and reflected cross-site scripting.
guests.php:208, init.php:982, seatgen.php:29