Description
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2014-0461 Vulnerability (CVE-2014-0461)
WordPress Plugin Image Gallery-Responsive Photo Gallery SQL Injection (1.0.6)
WordPress Plugin Lana Email Logger Cross-Site Scripting (1.0.2)
WordPress Plugin Easy Coming Soon Cross-Site Scripting (1.8.1)
WordPress Plugin WP Job Manager PHP Object Injection (1.31.2)