A cross-site scripting (XSS) vulnerability in miniTCG v1.3.1 beta allows attackers to execute abritrary web scripts or HTML via injecting a crafted payload into the id parameter at /members/edit.php.
| Software | From | Fixed in |
|---|---|---|
| heavenspell / minitcg | 1.3.1-beta | 1.3.1-beta.x |