Description
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
Remediation
References
Related Vulnerabilities
WordPress Plugin Magn WP Drag and Drop Upload Arbitrary File Upload (1.1.4)
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.9.10)
WordPress Plugin Newsletter-Send awesome emails from WordPress Unspecified Vulnerability (4.1.1)
WordPress Plugin SnapApp Multiple Cross-Site Scripting Vulnerabilities (1.5)