Medium
CVSS 4.3
Overview
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before ...
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: