Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.
| Software | From | Fixed in |
|---|---|---|
| dotclear / dotclear | - | 2.9.1.x |