CVE-2014-100008
13.01.2015, 11:59
Cross-site scripting (XSS) vulnerability in includes/delete_img.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter.
Vendor | Product | Version |
---|---|---|
joomlaskin | js_multi_hotel | 𝑥 ≤ 2.2.1 |
𝑥
= Vulnerable software versions