Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in Metinfo 5.3.18 allows remote attackers to inject arbitrary web script or HTML via the (1) class1 parameter or the (2) anyid parameter.
| Software | From | Fixed in |
|---|---|---|
| metinfo / metinfo | 5.3.18 | 5.3.18.x |