Stored Self XSS in Croogo Affects Various Versions
CVE-2019-7171
4.8MEDIUM
What is CVE-2019-7171?
A stored self XSS vulnerability exists in Croogo versions prior to v3.0.5, allowing attackers to inject and execute HTML or JavaScript code via the Title field in administrative block editing. This can lead to unauthorized actions and data exposure, making it crucial for users to apply the necessary patches and updates to secure their applications.
