Cross-site scripting (XSS) vulnerability in x_stat_admin.php in x-stat 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a parameter to the phpinfo action.
| Software | From | Fixed in |
|---|---|---|
| xqus / x-stat | 2.3 | 2.3.x |
| xqus / x-stat | 2.2 | 2.2.x |