majordomo
majordomo copied to clipboard
XSS in modules\thumb\enlarge.php
Here is a xss vulnerability in modules\thumb\enlarge.php about parameter close. POC:
http://your-web-root/modules\thumb\enlarge.php?close="><script>alert(1);</script><"
This poc will pop a window in FireFox browser.
FireFox - working IE11 - don't working Chrome - don't working