Subsonic 6.1.1 Persistent XSS

Discussion in 'News Aggregator' started by Packet Storm, 5 Jun 2017.

  1. Packet Storm

    Packet Storm Guest

    Remote attackers can abuse the "Subscribe to Podcast" feature of Subsonic 6.1.1 to store persistent XSS payloadsif an authenticated user clicks a malicious link or visits an attacker controlled webpage.

    Continue reading...
     

Share This Page

Loading...