Description
An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.
Remediation
References
Related Vulnerabilities
Drupal Core 8.9.x Cross-Site Scripting (8.9.0 - 8.9.13)
WordPress Plugin Stylish Price List Security Bypass (6.9.0)
WordPress Plugin FireDrum Email Marketing PHP Object Injection (1.47)
WordPress Plugin Venture Event Manager Cross-Site Scripting (3.2.4)
Oracle Database Server CVE-2020-2518 Vulnerability (CVE-2020-2518)