Skip to content
ביקורת אבטחה
חזרה ללוח
D58אומת בקודP2

Stored XSS: event ACF fields + seat-map JSON unescaped into front templates

C · authS3 · destructiveSECT2
תיקון
88%
מורכבות low

Event fields and seat-map data render unescaped into front-end templates, allowing stored cross-site scripting.

checkout/events/web.php:30, steps/seater.php:19