An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS).
This Cyber News was published on www.tenable.com. Publication date: Sat, 26 Oct 2024 03:26:02 +0000