Headline
CVE-2021-39486: Gila CMS Vulnerabilities | Navid Kagalwalla
A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, passwords or to run arbitrary code on a victim’s browser.
Related news
CVE-2021-38822: IceHrm Vulnerabilities | Navid Kagalwalla
A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that allows for arbitrary execution of JavaScript commands.