Hi, In my opinion, this XSS vulnerability could be used with a CSRF vulnerability (if found). An attacker could send a HTML page to the victim that execute a automatic/hidden POST request. Enviado via e-mail seguro de Proton Mail. ------- Original Message ------- Em quinta-feira, 9 de junho de 2022 às 7:58 PM, Ilia iliajie@users.sourceforge.net escreveu: Thanks for reporting this. We will look into fixing this. Although, can you think of a real life exploitation of this bug, when this attack could...
Cross-site scripting (XSS) Stored in Usermin's "Manage Folders" and "Address Book"