Description
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (6.1.2)
WordPress Plugin Advanced Advertising System PHP Object Injection (1.3.1)
MyBB CVE-2015-2352 Vulnerability (CVE-2015-2352)
WordPress Plugin Password Protected Unspecified Vulnerability (2.0)
WordPress Plugin Duplicator-WordPress Migration Cross-Site Request Forgery (1.1.2)