Description
Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.
Remediation
References
Related Vulnerabilities
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-41892)
WebLogic CVE-2021-2033 Vulnerability (CVE-2021-2033)
Moodle Improper Privilege Management Vulnerability (CVE-2023-5549)
WordPress Plugin Content Control-User Access Restriction Cross-Site Scripting (1.1.9)