Beveiligingsadvies

CVE-2021-24435

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-09-06 11:09:24
Laatst bijgewerkt 2024-08-03 19:28:23
Toegewezen door WPScan
CVSS-score geen score
Status PUBLISHED

Beschrijving

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues