The parameters first_name and last_name in Users are vulnerable from XSS-Reflected on Paymoney-3.3. The already authenticated users can be hijacking the XSRF-Token and they can use it for malicious purposes on internal and external domains.
Medium
The parameters first_name and last_name in Users are vulnerable from XSS-Reflected on Paymoney-3.3. The already authenticated users can be hijacking the XSRF-Token and they can use it for malicious purposes on internal and external domains.
Medium