Description
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Remediation
References
Related Vulnerabilities
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7911)
Drupal Core 7.x Remote Code Execution (7.0 - 7.74)
WordPress Plugin ACF Frontend display Arbitrary File Upload (2.0.5)
WordPress Plugin Travelpayouts:All Travel Brands in One Place Cross-Site Scripting (0.7.12)
WordPress Plugin Import any XML or CSV File to WordPress Arbitrary File Upload (3.2.3)