
| Researchers | DotAdrien |
| Severity | 8.5 (HIGH) (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N) |
| Software | Script Pag |
A stored Cross-Site Scripting (XSS) vulnerability exists on the homepage via the "Recent Ads" module. The image URL field fails to sanitize double quotes ("). An attacker can inject a payload such as https://google.com/image.png", which triggers when any user visits the homepage.