Description
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could inject arbitrary HTML and script code into a browser in the context of the vulnerable website.
Remediation
References
Related Vulnerabilities
Apache Tomcat Other Vulnerability (CVE-2002-1148)
Coppermine Cross-site Scripting (XSS) Vulnerability (CVE-2015-3921)
Plone CMS Improper Input Validation Vulnerability (CVE-2011-4462)
Squid Improper Input Validation Vulnerability (CVE-2019-12520)
WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1)