MSA-08-0009: Persistent Cross-site Scripting (XSS) on blog entry title parameter | |||||||||||||
Description: ProCheckup discovered that 1.6.x and 1.7.x sites with enabled blogs are vulnerable to persistent Cross-site Scripting (XSS) attacks through blog entry titles. We would like to thank them for informing us in a responsible manner and coordinating the disclosure of security advisories. |
