Opensis-Classic Version 8.0 is affected by cross-site scripting. An unauthenticated user can inject and execute JavaScript code through the link_url parameter in Ajax_url_encode.php.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view