Description
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
Remediation
References
Related Vulnerabilities
Django Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-23833)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2021-4104)
WordPress 'wp-login.php' HTTP Response Splitting Vulnerability (1.2)
WordPress Plugin Haiku minimalist audio player Cross-Site Scripting (1.0.0)