Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestName parameter.
| Software | From | Fixed in |
|---|---|---|
| lussumo / vanilla | 1.1.7 | 1.1.7.x |
| lussumo / vanilla | 1.1.5 | 1.1.5.x |