Description
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.
Remediation
References
Related Vulnerabilities
GlassFish CVE-2017-10393 Vulnerability (CVE-2017-10393)
WordPress Plugin Pressbooks Cross-Site Scripting (2.4.2)
WordPress Plugin Book appointment online Cross-Site Scripting (1.38)
WordPress Plugin Easy Comment Uploads 'upload.php' Arbitrary File Upload (0.61)
WordPress Plugin WP-Forum Multiple SQL Injection Vulnerabilities (2.3)