Description
The course upload preview contained an XSS risk for users uploading unsafe data.
Remediation
References
Related Vulnerabilities
MODX Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2017-9069)
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2005-0227)
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.6.0)
WordPress Plugin Simple File List Arbitrary File Download (3.2.7)