<p>Please fix the guestbook XSS<br><br>**Stored XSS**</p><p>Normal users can store an XSS payload in rich-text content, confirmed in news comments and likely guestbook</p><p>Example impact: attacker posts an image payload in a comment; when another user/admin hovers or opens the rendered image, JavaScript runs in their browser.</p><p>**Arbitrary Upload Delete**</p><p>Example impact: attacker guesses existing shared file IDs, creates a news comment referencing them, then deletes their own comment; the CMS deletes files that may belong to other users/content.</p>
Chifty 6 мая 2026 г., 19:09
Fixed. Thanks 🤠