天下漏洞,尽知其名
MEDIUM

CVE-2016-20098 Moderator Toolbox 存储型跨站脚本漏洞

原始情报

Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators’ Reddit sessions.