Description
Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.
Remediation
References
Related Vulnerabilities
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.30)
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2020-11067)
WordPress Plugin Simple Security Multiple Cross-Site Scripting Vulnerabilities (1.1.5)
WordPress Plugin Qe SEO Handyman SQL Injection (1.0)
WordPress Plugin WP Limit Login Attempts Security Bypass (2.6.4)